URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 23.94.99.117
Firstseen:2023-02-13 09:03:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-13 09:03:11 23.94.99.11723-94-99-117-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-22 16:23:05http://23.94.99.117/2341/vbc.exeOfflineAgentTesla ext exe opendir abuse_ch
2023-03-08 21:09:06http://23.94.99.117/3591/vbc.exeOfflineAgentTesla ext exe opendir rat RemcosRAT ext abuse_ch
2023-02-13 09:03:11http://23.94.99.117/5428/vbc.exeOfflineAgentTesla ext exe RemcosRAT ext SnakeKeylogger ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-22 16:23:0514dc4992e993f0b0b7b176ee8dd0314ab77e1512e6319f0369b6f9fe45369297exeAgentTesla
2023-03-20 14:51:45bb4297e1d60fbf0c9670f3a436d3c00993307ccf5bbf9bade4a6ebcb608edd6cexeAgentTesla
2023-03-20 11:38:155fc747d77faaedb0459b4e9fb8dbef1912f6fa91ad088a3ec016c749ecd83022exeAgentTesla
2023-03-20 07:31:4466d51327bab933eda9d755eb691e584fcb324b04c573d1be50d634c7297134f8exeAgentTesla
2023-03-20 06:17:2265cc1ea27c733c270dd0497ed9c99896baf50eeafa5e1200889557985bfd87d5exeAgentTesla
2023-03-18 21:27:342d375d705eba9a464fd1ebd8d4f15adf3e7e62b16fb0f5b41f96d1872040edf7exe 
2023-03-17 06:27:482e88105d979bfbe65b2ed9322114fc21ef9e1fdb324a63d6198defd1e976d36eexeAgentTesla
2023-03-16 20:01:11462b121f72bc42fcefcfc67174e4de53083b977458c7ed3d4009eec6bddd3f1bexeAgentTesla
2023-03-09 11:39:0078b009999d967e2d3eeb4a10ce91c84048dc566d2a74d8e223a6a5b15db5839bexeRemcosRAT
2023-03-09 07:42:2314f6d15b3a4940f6cbda03673df4867785286b798c87d36ece18ddccd5dce084exe RemcosRAT
2023-03-09 06:43:369184cd81781503972e53fc34d26c401e791b6425b25a78473e369ec4a97ac7a7exe RemcosRAT
2023-03-08 21:09:06cf6de5f333dea0ffbc94ef944a23c99db28e66e7d51757d01a9a017a21fb8837exeRemcosRAT
2023-03-02 05:16:5602ced6da9cf24901681948deae308d36975cb623dcc6735f2142f4252bc7e197exeRemcosRAT
2023-03-01 14:21:109f9f3096c804ba3921cfbdbcc3e2f877ab7d3f5f0e2d264be739c485fd02ccd8exeRemcosRAT
2023-02-13 09:03:05e1cfaf8c115404150c4bae0e2210c47862cdc5f12b0e2054bd5afd4ce6569737exeSnakeKeylogger