URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 69.48.201.40
Firstseen:2025-03-20 09:58:05 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-20 09:58:17 69.48.201.40ip69-48-201-40.pbiaas.comNot listedAS8560 IONOS-AS- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-27 23:59:32http://69.48.201.40/255/ssen/oybestgirlformybes...Offline DaveLikesMalwre
2025-03-20 10:00:10http://69.48.201.40/255/ssen/oybestgirlformybes...Offlinedoc RemcosRAT ext NDA0E
2025-03-20 09:59:12http://69.48.201.40/255/hemybestgirlformybestki...Offlinehta RemcosRAT ext NDA0E
2025-03-20 09:59:06http://69.48.201.40/255/mybestgirlformybestkiss...Offlineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2025-03-20 09:58:18http://69.48.201.40/xampp/c/ENCRYPTION01.jpgOfflineascii Encoded jpg-base64-loader NDA0E
2025-03-20 09:58:17http://69.48.201.40/xampp/c/new_image.jpgOfflineascii Encoded jpg-base64-loader NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-20 10:26:01c1821b2389018bb005e46d5392fc14878c05dcba9aa64e847fb563301b0b036btxtRemcosRAT
2025-03-20 10:00:10a24310c67d333ac8b3ffd7b1a9d0354a7024d24dcc062774ca0fe6d0f67f05cfrtfRemcosRAT
2025-03-20 09:59:1152735867c3b5666531b495c5954353cd364315de484d930102936685e28efe4chtaRemcosRAT
2025-03-20 09:58:170ff5dd1787acc886a586282858112c6f73b48c31093080d2d8a6e66f018ce8c7jpg  
2025-03-20 09:58:16bac526ce5b84717f141b16543f67a6c1462a558f9c28719cb813eb337babe39ejpg