URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.213.50.74
Firstseen:2022-12-20 07:45:05 UTC
Total malware sites :43
Online malware sites :0 (0%)
Offline Malware sites :43 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-12-20 07:45:11 91.213.50.74Not listedAS49943 UNKNOWN- AEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-09-08 09:55:10http://91.213.50.74//CRYPS/Q9/dll3f3.txtOfflineAnonymous
2023-09-08 09:55:09http://91.213.50.74//CRYPS/Q9/PeF3.txtOfflineAnonymous
2023-07-08 10:41:13http://91.213.50.74/new/mofers/SP/Q2s.txtOfflineHTI QuasarRAT ext JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/new/mofers/Rmz.txtOfflineHTI RemcosRAT ext JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/new/mofers/T3.txtOfflineHTI QuasarRAT ext JAMESWT_MHT
2023-07-08 10:41:13https://91.213.50.74/CRYPS/Q7/dllF3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/GREEN/RX/nuevadll.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/new/mofers/R.txtOfflineHTI RemcosRAT ext JAMESWT_MHT
2023-07-08 10:41:13https://91.213.50.74/CRYPS/Q7/QWER/dllf3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/new/mofers/Q7.txtOfflineHTI QuasarRAT ext JAMESWT_MHT
2023-07-08 10:41:13http://91.213.50.74/new/mofers/Rm.txtOfflineHTI RemcosRAT ext JAMESWT_MHT
2023-07-08 10:41:12https://91.213.50.74/CRYPS/QWERS/NEW23/Pef3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/Q1.txtOfflineHTI QuasarRAT ext JAMESWT_MHT
2023-07-08 10:41:12https://91.213.50.74/CRYPS/QWERS/MASTERXLS/dll.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/Async.txtOfflineAsyncRAT ext HTI JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/Arrw.txtOfflineAsyncRAT ext HTI JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/njx.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/ZX2.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/Nx.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/SP/MC/BANDI99.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/ny1.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:12https://91.213.50.74/CRYPS/QWERS/NEW24/Pe03.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:12http://91.213.50.74/new/mofers/Lx6.txtOfflineGozi ext HTI JAMESWT_MHT
2023-07-08 10:41:12https://91.213.50.74/CRYPS/QWERS/NEW25/crypdas.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:12https://91.213.50.74/CRYPS/QWERS/NEW24/dllF3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:11https://91.213.50.74/CRYPS/Q7/QWER/PeF3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:11https://91.213.50.74/CRYPS/Q7/PeF3.txtOfflineHTI JAMESWT_MHT
2023-07-08 10:41:11https://91.213.50.74/CRYPS/QWERS/MASTERXLS/PeF3...OfflineHTI JAMESWT_MHT
2023-07-08 10:41:11http://91.213.50.74/new/mofers/SP/nxj.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:11http://91.213.50.74/new/mofers/NJ.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 10:41:11http://91.213.50.74/new/mofers/Arhvn.txtOfflinearrowrat HTI JAMESWT_MHT
2023-07-08 10:41:11http://91.213.50.74/new/mofers/L8.txtOfflineGozi ext HTI JAMESWT_MHT
2023-07-08 09:44:08http://91.213.50.74/CRYPS/QWERS/NEW24/dllF3.txtOfflineHTI JAMESWT_MHT
2023-07-08 09:44:06http://91.213.50.74/new/mofers/njz.txtOfflineHTI njRAT ext JAMESWT_MHT
2023-07-08 09:44:06http://91.213.50.74/CRYPS/QWERS/NEW24/Pe03.txtOfflineHTI JAMESWT_MHT
2022-12-21 17:44:03http://91.213.50.74/GREEN/RX/F3Pe.txtOfflineEncoded HTI opendir abuse_ch
2022-12-21 17:44:03http://91.213.50.74/GREEN/ZXC/ZAS/PeF3.txtOfflineEncoded HTI opendir abuse_ch
2022-12-21 17:44:03http://91.213.50.74/GREEN/RXWER/fePe.txtOfflineEncoded HTI opendir abuse_ch
2022-12-21 17:44:03http://91.213.50.74/GREEN/RX/F3dll.txtOfflineascii Encoded HTI opendir abuse_ch
2022-12-21 17:44:03http://91.213.50.74/GREEN/RXWER/dllf3.txtOfflineascii Encoded HTI opendir abuse_ch
2022-12-21 17:44:03http://91.213.50.74/GREEN/ZXC/ZAS/dllf3.txtOfflineascii Encoded HTI opendir abuse_ch
2022-12-20 07:45:11http://91.213.50.74/CRYPS/QWERS/MASTERXLS/PeF3N...OfflineHTI opendir abuse_ch
2022-12-20 07:45:11http://91.213.50.74/CRYPS/QWERS/MASTERXLS/dll.txtOfflineHTI opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-09-08 09:55:1013f41cb094f8309fe7dd8bd2f9fbd00b3ebba7cf1bc7c7e291bd66de47674209txt  
2023-09-08 09:55:092ec21015cffee98b03d33b86f65c0b526ed158dab745521dcf50a10d23d07808unknown  
2023-07-08 10:41:13dbc597c5a4c532eb959740dffe368cf27605bb9793e30f87530d10efe1ebb8dctxtQuasarRAT
2023-07-08 10:41:13e0bede137de510fa9d07894fc2475c5c38af0832cee1871239a2c8456ce7cf20txtRemcosRAT
2023-07-08 10:41:13a5b87e0f2c2c7af9a3cb1985d40189cbff8570eb422f3c2d57c0c2075dfad868txtQuasarRAT
2023-07-08 10:41:13495111e2591171e474a815e040b4587d11d5e977a15e7113580de3fcfb9ac31ftxt 
2023-07-08 10:41:13bc21f48e11d231619118d5da2ce1d12e280df3d17bcc941c61573268d8767140txt 
2023-07-08 10:41:1304fb07737340a94a11abb38b3974a769fd279ff55584d8d49a13b75db08c3a03txtRemcosRAT
2023-07-08 10:41:1348c3854a498d317a6c0c080fcf3524a92b4f3832f0fdd9481818deaff1153c46txt 
2023-07-08 10:41:138a66611c1d86e124ae32ce868c14233d207214cb76b4db455b61ec5560997b29txtQuasarRAT
2023-07-08 10:41:13aca4b3dbb9a0b1906c0dce0611793cbb0185e1488d3be8dbbeb2675f9e1cdeaatxtRemcosRAT
2023-07-08 10:41:1222ab868dc3bb87e327d0de4d0aedddc70200d47d926ce214aab0bf3230f71252unknown 
2023-07-08 10:41:12d3aa396166cf4fc7140274d78bde2ea9b0eb3c8377dee376f300b403eacc0f76txtQuasarRAT
2023-07-08 10:41:12dea9e66ac7d4d4cc192aa0531f7db465e5515fd2eced757cedb7b49dede7cdcdtxt  
2023-07-08 10:41:128258161e3174011d59ba5f8282a0663382808c28d950857d2c7812a951d9fc57txtAsyncRAT
2023-07-08 10:41:129e4d78a77e7c42b5fe49dc1ed7c9f63e55eb1c770c6b16ef4e809740b2975a38txtAsyncRAT
2023-07-08 10:41:129cd155a2837a0fdecac6c216073d3bfb453af6ec4d7cf0ff1cab29acf225ee61txtnjrat
2023-07-08 10:41:12bc4c6e2474a909a87e28069445395b09b2a3e3c39f11a81bcffb7cc2632837actxtnjrat
2023-07-08 10:41:12539690a71dd05fed9d139014f8414b0686013b28c30a52d5851e1d3e86e4cf28txtnjrat
2023-07-08 10:41:129cb948d6e1acedc51461083dc37d0ba8f74e73387689a98b69c889b87417ecb6txtnjrat
2023-07-08 10:41:129a849b3d91f1ed4292fd3e2a87d6dc0cdb057fae3d930993bab478523185182etxtnjrat
2023-07-08 10:41:12d27224eb9e5c34abfb22ba1941f3c4c4fbcfb5702899f8cf4fe280f4aa881d44unknown 
2023-07-08 10:41:11da939debbc7d60ce6ccd27767d7c4256615e00912aa22a46ad2805bebe3427b1txtGozi
2023-07-08 10:41:1107a4efc6a7b6d211c4d268c283974a9913a1ff9bdffe15a68d6542c586e728e5unknown 
2023-07-08 10:41:11e33b9f53889aab6e8f4fa9d379f3d1d6deac712593106be0102e764252031609unknown 
2023-07-08 10:41:11235a4869a9e7f44b283da1bac05aed36337ffb44e6cb362f2e2ad58a1431e37eunknown  
2023-07-08 10:41:11083c50e6b9875fe5df15be50193a5c55331e613498f419388475fdd5f726d611txtnjrat
2023-07-08 10:41:11dc5c428eb8a77c488cd8617ee11af404a9cec464a82b3741de48bec8d7b046d4txtnjrat
2023-07-08 10:41:11d3431fb4f3d309dad981f5c725c15cbca5ce4d00801b7d92d0bb6c420c9a3df7txtArrowRAT
2023-07-08 10:41:115d598e3afe8736c96f6d2cc0a6509b12e9fc15d45afc070e7e9d5bd68946335etxtGozi
2023-07-08 10:41:11fb19dd60cf30e2c61634df2042c588f84882097e142d9e7b4ab1faebb974338atxt 
2023-07-08 10:41:1162590723dffc946a4facb19c7da058a68ffd373041eff35a842f621c1835a1d6txt 
2023-07-08 09:44:08fb19dd60cf30e2c61634df2042c588f84882097e142d9e7b4ab1faebb974338atxt 
2023-07-08 09:44:067e4eefbc013cf9c3d650eb309727a995fab17e7661308217aa8eab12d6fa7bbatxtnjrat
2023-07-08 09:44:06d27224eb9e5c34abfb22ba1941f3c4c4fbcfb5702899f8cf4fe280f4aa881d44unknown 
2022-12-21 17:44:038987f0b4fe2f98f7259dff4b9771dabeba91719c7d6fce23f8b857f03654fa1funknown  
2022-12-21 17:44:039c94f952040977778e549aae5543c35db95f4751d609e07b8d4f63454e00e8eaunknown  
2022-12-21 17:44:038987f0b4fe2f98f7259dff4b9771dabeba91719c7d6fce23f8b857f03654fa1funknown  
2022-12-21 17:44:03b763f10da58edab82a8ee9b8ffe65574fe29813b49aad265d213dc7466780a26txt  
2022-12-21 17:44:03ab7d6bdb566bd34ee6cc24d25da4d634b65576c5dc944bbc31e44f281630fce6txt  
2022-12-21 17:44:031bca26359d4341e3bad1bbaa78c77deb94863b9517c480e15bd8a2c4f9aa67e4txt  
2022-12-20 07:45:06235a4869a9e7f44b283da1bac05aed36337ffb44e6cb362f2e2ad58a1431e37eunknown  
2022-12-20 07:45:06dea9e66ac7d4d4cc192aa0531f7db465e5515fd2eced757cedb7b49dede7cdcdtxt