URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 54.79.28.10
Firstseen:2022-11-23 09:15:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-23 09:15:11 54.79.28.10ec2-54-79-28-10.ap-southeast-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- AUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-11-25 08:05:06http://54.79.28.10/000000_0000000_000000_000000...Offlinedoc opendir rat RemcosRAT ext abuse_ch
2022-11-25 08:04:08http://54.79.28.10/260/vbc.exeOfflineexe opendir rat RemcosRAT ext abuse_ch
2022-11-23 09:15:14http://54.79.28.10/270/vbc.exeOfflineRemcosRAT ext Anonymous
2022-11-23 09:15:11http://54.79.28.10/000000_0000000_000000_000000...OfflineAnonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-11-25 08:05:0624f6f0cc2f1288a6559c4382aa8665a2884be807f6206f92aa2332ef28ffca2bunknown  
2022-11-25 08:04:087a5870c5e7f9253deca223afcbf295a99ad0cc014543b26e162e56ad2f22a36eexeRemcosRAT
2022-11-23 09:15:090cb9ffbc77206540a648b96e790d884f5662c114e831533e1eb31b63157e3953exeRemcosRAT
2022-11-23 09:15:054fa6fa88abee41384a1f11b2bb8ee81cb0468c2a3c9976b5d6998635301152b1unknown