URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 6f841a9a-243d-4072-8e01-b07a63e328cd.random.tbtt.duckdns.org
Domain registrar:Gandi -
Domain registration date:2013-04-12 19:58:56 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-06-13 01:18:09 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-13 01:18:26 181.206.158.190Dinamic-Tigo-181-206-158-190.tigo.com.coNot listedAS27831 Colombia_Mvil- COno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-06-13 01:18:38http://6f841a9a-243d-4072-8e01-b07a63e328cd.ran...Offlineopendir RemcosRAT ext Riordz
2025-06-13 01:18:27http://6f841a9a-243d-4072-8e01-b07a63e328cd.ran...Offlineopendir RemcosRAT ext Riordz
2025-06-13 01:18:26http://6f841a9a-243d-4072-8e01-b07a63e328cd.ran...OfflineAsyncRAT ext opendir Riordz
2025-06-13 01:18:21http://6f841a9a-243d-4072-8e01-b07a63e328cd.ran...Offlineopendir Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-07-18 17:34:54d7ebd5189406570fb7f202a1ab8095526b776d155e118fe207fd51e98c6f941cvbsRemcosRAT
2025-07-02 16:37:0353de468d8098c2d3a611e96c04e244d95a136d5a75567973e89e72fcc8e896fbtxt AsyncRAT
2025-07-02 14:22:05e9e6b5fc76e944d6b5bedcc3fc4ccd374082af41547d9444009e5b1923c0d808txt RemcosRAT
2025-07-01 10:39:54a2727b617e87d1c8070d69cf1c5fa58c757ae0e425c26c049dce311e1adb5745txt 
2025-06-28 23:08:331bbe72db7edc9646e243e57b06a23d0d00bcf72413c719f87a9131cf1968afdftxt  
2025-06-28 22:40:455da646edf1eed3abc74e49e1a9daf4e4e5bedb7a1652ca3311cd7f8bce650babtxt RemcosRAT
2025-06-28 22:11:36aaab431dab3880838f6be9e7eec86c82b0631029d4f804e91a39cd46596ca983txt RemcosRAT
2025-06-26 16:58:027cc4edef464d473ad938087c7ab1fade6c6915310bf406a42b89f11e8a4bebdetxt  
2025-06-25 17:30:194ec31eaddf0cfa91904708d2cb6d9abd67fe416ae515d4f11382bd27b697a48ftxt  
2025-06-24 05:03:23b39a0af289058c72bdc7ad5530c2855a950db8914239c662be14847475ac8ed4txtRemcosRAT
2025-06-23 21:48:136cef2a9dfe5e84b67c901ff1e8d8544ed3f763b47a462f9014f3674db182e464txtAsyncRAT
2025-06-23 15:59:131311aed7b08093746c808edea41d40fb2e8547a1bd86a2516cf7bf4f1f2075fdtxtRemcosRAT
2025-06-19 23:19:50d34e2b0175f4ac43db01915f93ebedcf1060c64eca971e81ca0f4c182b159a15txt  
2025-06-19 23:02:261f2b56088d222e368d334f66e85e20ad542c2e68e384a374b99b72722d9e5ddctxt  
2025-06-18 22:52:20a7ea2f8cf65a2fc6368cbe91431080aa1269cc37de7095a15237d1b411f27d93txtRemcosRAT
2025-06-18 22:49:51fd43d26f1db150f1ce6faa221521e0ac9d32ffc26fc835bdc564ce6d93a5ee84txtRemcosRAT
2025-06-18 22:32:29b13e974aa3bb30239ff57db566dac32c1c19a2323eecbb785890224549444254txtAsyncRAT
2025-06-17 23:37:22c3ba98565b219c4fe9a0bc2a10e6a5624133d92e8eaed9ec0c5e3be7ba2951eetxtRemcosRAT
2025-06-17 23:16:4980266097de62073344ac4e0caf95a2ebbcd9d6bda282cf72a87e485026d6d7ectxt 
2025-06-17 22:40:20cfdc2ae6a13e3aec697ff5535644d20bad1bae878d39ba2f56af905a8ab039d4txtRemcosRAT
2025-06-17 04:56:263c456a7c35a2a9d3a4a69e51adda6eb1aa3e35369e11e1ec07988379c1ebb8c2txtRemcosRAT
2025-06-17 04:49:5504e5f143418bd25e995f0ae658891b2b678537128bdce1f9bf048b9473df943ctxt 
2025-06-16 16:53:475289ae56de34e2a10a649deedbc33133911ae1c7d713e7d0451bd2780b7a9c66txt RemcosRAT
2025-06-13 01:18:25c3f63740392bb5974a1c10ef9d0a26394f1ddb548c6121d31a4a845d86cd00bdtxtAsyncRAT
2025-06-13 01:18:22198daaa357fea1d108030cc062789b217dc982c71f761a3eaa6ae06545776fc4txtRemcosRAT