URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 79.110.49.21
Firstseen:2023-06-27 06:06:09 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-06-27 06:06:11 79.110.49.21Not listedAS399486 VIRTUO- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-06-29 05:57:06http://79.110.49.21/secgovernorzx.exeOffline32 AgentTesla ext exe zbetcheckin
2023-06-29 05:18:05http://79.110.49.21/davincizx.exeOffline32 exe Loki ext zbetcheckin
2023-06-29 04:29:04http://79.110.49.21/dollzx.docOfflineAgentTesla ext RTF zbetcheckin
2023-06-28 14:26:05http://79.110.49.21/owenzx.exeOfflineexe Formbook ext abuse_ch
2023-06-28 14:25:06http://79.110.49.21/pmexzx.exeOfflineAgentTesla ext exe abuse_ch
2023-06-28 08:31:03http://79.110.49.21/defounderzx.exeOffline32 exe Formbook ext zbetcheckin
2023-06-28 06:31:05http://79.110.49.21/thirdagodzx.exeOfflineexe Formbook ext abuse_ch
2023-06-28 06:26:04http://79.110.49.21/dollzx.exeOfflineAgentTesla ext exe abuse_ch
2023-06-28 06:09:34http://79.110.49.21/thirdagodzx.docOfflineFormbook ext RTF zbetcheckin
2023-06-28 05:21:07http://79.110.49.21/chamberszx.exeOffline32 AgentTesla ext exe zbetcheckin
2023-06-28 04:35:07http://79.110.49.21/papizx.exeOffline32 exe RemcosRAT ext Rhadamanthys zbetcheckin
2023-06-28 03:55:06http://79.110.49.21/kudizx.exeOffline32 AgentTesla ext exe zbetcheckin
2023-06-28 03:55:06http://79.110.49.21/plugmanzx.exeOffline32 exe RemcosRAT ext zbetcheckin
2023-06-28 03:54:04http://79.110.49.21/gvailantzx.exeOffline32 AgentTesla ext exe zbetcheckin
2023-06-27 06:31:09http://79.110.49.21/ansazx.exeOfflineexe Formbook ext abuse_ch
2023-06-27 06:06:11http://79.110.49.21/agodzx.exeOfflineAgentTesla ext exe Formbook ext abuse_ch
2023-06-27 06:06:11http://79.110.49.21/agodzx.docOfflineAgentTesla ext doc Formbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-07-16 00:08:55a4fc086a6ee943665825c08590dab011a51032294eed1c7971bb5bd9308868fbexe  
2023-07-14 13:38:1163d564ee18cc7272f401612a4aa845c2f1be023f83cb1d851ff8f2986082927bexeRhadamanthys
2023-07-14 10:03:336666bd3cfd70f1e45584b1a6ff5820e2717e177d32ed196201306ef99c957cc7exeAgentTesla
2023-06-30 04:32:5853e575805dc9d69c41f366e65946a7d4adf051f322f463f70e9b2f80d50450cbexeAgentTesla
2023-06-30 04:08:48df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4baexeRemcosRAT
2023-06-29 21:33:31d088a3c1bbc7b1c97e5ce94d4a2e1f8ed7fcf7cef8e2b21d70ee15bb3f49d509exeFormbook
2023-06-29 21:20:47b8affa2c64dd1a3661fd9ea46581ea09b733871562c2d080f2c81923e7275961exeAgentTesla
2023-06-29 20:03:09cd917c86fe27ecd3feeca690377817bce1f4034830e6d68a19dbffc8c61e97bbexeAgentTesla
2023-06-29 20:02:552e29e6a4b0be6fc27da448eec0e9f06757ed24399cd33af0b113f51062fe6608exeAgentTesla
2023-06-29 19:24:034b40e11d7fcbf9eb1f49889af19bc26a8c3ef6faaf2c8614919d1ee0ef8f2ff1exeAgentTesla
2023-06-29 17:09:1649e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6exeRemcosRAT
2023-06-29 10:20:41f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20eexeRemcosRAT
2023-06-29 05:57:06e57c444a50a0cb9ac14152220923763532f8a280c37ff45ee55ef28844740434exeAgentTesla
2023-06-29 05:18:0401884b7d8e2c9bde09bec45e9258fec0b4b5db58f9852be8dbd6a0c55180bd23exeLoki
2023-06-29 04:29:04302ce92ae8d85935b145432eba8d7adafb095990dd1f7d873a2eeec87f413011rtfAgentTesla
2023-06-28 14:26:0562d79b7612daa665c7f2769bad890f7d42fc26849f0baa1c596e601b0a724057exeFormbook
2023-06-28 14:25:06259f1fbe74a74d7a536397bde987a0531e5479827da769a22e125a1d6840103aexeAgentTesla
2023-06-28 08:31:03c81c9ba400d187e3f9ddbc3c9b31a5ac9ae2d102969a30d0896b19efd1981cebexeFormbook
2023-06-28 08:29:408b2a9586bcf26045ba196d4714d8c628feb5d8eed4604ff82c6e3625b67a9437exeAgentTesla
2023-06-28 07:47:2634bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1exeRemcosRAT
2023-06-28 07:29:24289e568e3f98aec8c5391f3a42298e9da0c1ce113b2406b33364bbcee2b2d6b0rtfAgentTesla
2023-06-28 07:26:311d0cf9a5e034371075cf0a328d98c53f4eeb74325d61ee956222346ebb1f5497exeAgentTesla
2023-06-28 06:41:00a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40exeRemcosRAT
2023-06-28 06:31:0587f7348a8731af0346cfcc709488d0831a95236f554d2f8a50e12eea1ceb6764exeFormbook
2023-06-28 06:29:38165b8d6325abf101bbdb36a6c67920679ec28b6fab20c5a26d60f11787aae618rtfFormbook
2023-06-28 06:26:04ccc2705cc016a910af89b39b5beeca2885eedd714cca5ab153b416c201d0ea96exeAgentTesla
2023-06-28 05:21:076e4b2204ab34ef1534d3c80e379e200f37a05e04ed2856d2df2f5983e9351ce6exeAgentTesla
2023-06-28 04:35:073da90b636e39cd1f67e3542c60d813c6ff8152f7f740b3ef4ef086ef120836dfexeRemcosRAT
2023-06-28 03:55:0608cd319446765afe2881c8391688baa55af8eeddfb6c334a522a5232fc3d4f09exeAgentTesla
2023-06-28 03:55:065e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920aeexeRemcosRAT
2023-06-28 03:54:04d6f97400d822eaccbf90e7a0dc62b32e8073ad22185c28c065eca47bda82e044exeAgentTesla
2023-06-27 06:31:09fa50f197e39eb37efdbd83462dd11e3057e45f88d9acb8b7e99c50c44c1936b7exeFormbook
2023-06-27 06:06:10dd625949ce3243dc01eaf5d1d270bef6d4f75a66995271553ea53ed8d3ba0a56rtfFormbook
2023-06-27 06:06:10ddcfb1ba424e8b10bc83301942845f50a4e5ada39250ba706a9ecbc7ee9e63e3exeFormbook