URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 91.241.19.159 |
|---|---|
| Firstseen: | 2020-12-19 13:07:03 UTC |
| Total malware sites : | 5 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 5 (100%) |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-12-22 15:53:02 | http://91.241.19.159/RT21.exe | Offline | exe | |
| 2020-12-22 11:52:04 | http://91.241.19.159/RT20.exe | Offline | exe RemcosRAT | |
| 2020-12-19 14:22:03 | http://91.241.19.159/RT16.exe | Offline | exe RemcosRAT | |
| 2020-12-19 13:08:03 | http://91.241.19.159/m7vvsw2dsQ/plugins/scr.dll | Offline | exe | |
| 2020-12-19 13:07:04 | http://91.241.19.159/m7vvsw2dsQ/plugins/cred.dll | Offline | Amadey exe |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-12-22 11:52:04 | 916becbd5800f23c51eadf90dcc159dd3986a97dfe545e76206731c92a576e5f | exe | RemcosRAT | |
| 2020-12-19 14:22:03 | 916becbd5800f23c51eadf90dcc159dd3986a97dfe545e76206731c92a576e5f | exe | RemcosRAT | |
| 2020-12-19 13:08:03 | e1596e399731ae19d1aeb1ffbe2349e9e71cad0980b025bd91a4dea93931bfd8 | dll | ||
| 2020-12-19 13:07:04 | a40037a0e743bcfa80bcc5ce9c761a0fad3d42d92a039d187d9d0ea294860bef | dll | Amadey |