URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 3.26.185.34
Firstseen:2022-03-21 08:33:03 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-21 08:33:04 3.26.185.34ec2-3-26-185-34.ap-southeast-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- AUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-04-12 12:26:07http://3.26.185.34/zb1.jpgOfflineascii NetWire ext powershell ps rat abuse_ch
2022-04-12 12:25:04http://3.26.185.34/zb2.jpgOfflineascii js NetWire ext rat abuse_ch
2022-04-08 09:28:07http://3.26.185.34/zp1.jpgOfflineascii powershell ps rat RemcosRAT ext abuse_ch
2022-04-08 09:27:04http://3.26.185.34/zp2.jpgOfflineascii js rat RemcosRAT ext abuse_ch
2022-04-01 13:41:07http://3.26.185.34/BG1.jpgOfflineascii rat RemcosRAT ext abuse_ch
2022-04-01 13:32:04http://3.26.185.34/BG2.jpgOfflineascii js abuse_ch
2022-03-31 08:39:06http://3.26.185.34/zz1.jpgOfflineascii Formbook ext powershell ps abuse_ch
2022-03-31 08:39:03http://3.26.185.34/zz2.jpgOfflineascii Formbook ext js abuse_ch
2022-03-29 07:06:07http://3.26.185.34/pat1.jpgOfflineascii powershell ps rat abuse_ch
2022-03-29 07:06:04http://3.26.185.34/pat2.jpgOfflineascii js rat abuse_ch
2022-03-28 07:36:07http://3.26.185.34/bb1.jpgOfflineascii powershell ps rat RemcosRAT ext abuse_ch
2022-03-28 07:36:04http://3.26.185.34/bb3.jpgOfflineascii powershell ps rat RemcosRAT ext abuse_ch
2022-03-21 08:35:08http://3.26.185.34/ep1.jpgOfflineascii powershell ps rat RemcosRAT ext abuse_ch
2022-03-21 08:35:05http://3.26.185.34/ep2.jpgOfflineascii js rat RemcosRAT ext abuse_ch
2022-03-21 08:33:07http://3.26.185.34/pd1.jpgOfflineascii powershell ps rat RemcosRAT ext abuse_ch
2022-03-21 08:33:04http://3.26.185.34/pd2.jpgOfflineascii js rat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.