URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 95.169.201.100
Firstseen:2024-12-04 12:42:04 UTC
Total malware sites :48
Online malware sites :0 (0%)
Offline Malware sites :48 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-04 12:42:06 95.169.201.100ip-95-169-201-100-114435.vps.hosted-by-mvps.netNot listedAS202448 mvps- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-04 13:07:05http://95.169.201.100:18960/build/readme.pdfOfflineSPAM-ITA JAMESWT_MHT
2024-12-04 13:06:05http://95.169.201.100:18960/readme.pdfOfflineSPAM-ITA JAMESWT_MHT
2024-12-04 13:06:04http://95.169.201.100:18960/build/readme.txtOfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:56:05http://95.169.201.100:18960/uploads/team-5/load...OfflineRhadamanthys SPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-3/load...OfflineRhadamanthys SPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-1/load...OfflineRhadamanthys SPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/test-2/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-3/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/test-1/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-5/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-4/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-1/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:09http://95.169.201.100:18960/uploads/team-2/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:06http://95.169.201.100:18960/uploads/team-5/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-1/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-5/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-4/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/ttest-1/rea...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-3/read...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-2/runn...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:55:05http://95.169.201.100:18960/uploads/team-3/runn...OfflineSPAM-ITA JAMESWT_MHT
2024-12-04 12:47:07http://95.169.201.100:18960/build/readme.exeOfflineexe Rhadamanthys abuse_ch
2024-12-04 12:46:14http://95.169.201.100:18960/readme.exeOfflineexe RemcosRAT ext abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/output/readme.exeOfflineexe Rhadamanthys abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/uploads/test-1/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/hercules.exeOfflineexe abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/uploads/test-2/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/uploads/team-3/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/uploads/team-5/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:10http://95.169.201.100:18960/uploads/team-4/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:09http://95.169.201.100:18960/uploads/team-1/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:46:06http://95.169.201.100:18960/output/readme.txtOfflineascii abuse_ch
2024-12-04 12:46:06http://95.169.201.100:18960/text.txtOfflineascii abuse_ch
2024-12-04 12:46:06http://95.169.201.100:18960/readme.txtOfflineascii abuse_ch
2024-12-04 12:45:13http://95.169.201.100:18960/uploads/team-3/read...Offlineexe Rhadamanthys abuse_ch
2024-12-04 12:45:13http://95.169.201.100:18960/uploads/test-2/read...Offlineexe abuse_ch
2024-12-04 12:45:12http://95.169.201.100:18960/uploads/team-1/read...Offlineexe Rhadamanthys abuse_ch
2024-12-04 12:45:12http://95.169.201.100:18960/uploads/test-1/read...Offlineexe abuse_ch
2024-12-04 12:44:05http://95.169.201.100:18960/uploads/test-1/load...Offlineascii Rhadamanthys abuse_ch
2024-12-04 12:44:05http://95.169.201.100:18960/uploads/test-2/load...Offlineascii Rhadamanthys abuse_ch
2024-12-04 12:44:05http://95.169.201.100:18960/uploads/team-4/load...Offlineascii Rhadamanthys abuse_ch
2024-12-04 12:44:04http://95.169.201.100:18960/uploads/test-2/read...Offlineascii abuse_ch
2024-12-04 12:44:04http://95.169.201.100:18960/uploads/test-1/read...Offlineascii abuse_ch
2024-12-04 12:44:04http://95.169.201.100:18960/uploads/team-4/read...Offlineascii abuse_ch
2024-12-04 12:43:05http://95.169.201.100:18960/uploads/team-2/runn...Offlinelnk Rhadamanthys abuse_ch
2024-12-04 12:43:04http://95.169.201.100:18960/uploads/team-2/read...Offlineascii abuse_ch
2024-12-04 12:42:06http://95.169.201.100:18960/uploads/team-2/load...Offlineascii Rhadamanthys abuse_ch
2024-12-04 12:42:06http://95.169.201.100:18960/uploads/team-2/read...Offlineexe Rhadamanthys abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-12-04 13:06:05cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:56:046f2860f34e4939a8053741edc66effe93162ae0d0a961d768cf3b34bdb1d4da2batRhadamanthys
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:09cf41e7881ec4a232f462ef0fc0e15c409619d18b3a8a84b49768268505af80e3pdf  
2024-12-04 12:55:091ea5cb9cd5320960aaa1f401db478e07a71582f7c610b4d4867c5b7629c13576batRhadamanthys
2024-12-04 12:55:088de3d851efc7e0d42da0ecbc656ab93362595101d30b36ce36b7d698cdd99cd0batRhadamanthys
2024-12-04 12:47:07e74135c647bb065e27f85b5bedb57b63c5731df0dd5d92877187be3cf6a2594eexeRhadamanthys
2024-12-04 12:46:1408c7fb6067acc8ac207d28ab616c9ea5bc0d394956455d6a3eecb73f8010f7a2exeRemcosRAT
2024-12-04 12:46:10ac3a503e94f241344f10f178fe378ac1f945ccd71a88c575622d91b376e3b6ecexe  
2024-12-04 12:46:105faffbfc993cbdaeb7b5e8f5f95f5510c340667ed5daff4b6f88d1ade8915208exeRhadamanthys
2024-12-04 12:46:10ec5a9c16784662f753009c9f7c8dd0c18ba4b59848ea2abef2fc831876119550lnkRhadamanthys
2024-12-04 12:46:10297c1ce4d6707d8ffdb7d80da5a19ce711a45de04f6089735130e237a7ba670clnkRhadamanthys
2024-12-04 12:46:109bf0166f4fdd3742a9336d5c847a3a99eb7262533642b549ab3aa6d7e72174e1lnkRhadamanthys
2024-12-04 12:46:10ab4273834ce472dd93c67f8a16d218f7e0be29ae6ead796579dc7ca35e82bb4clnkRhadamanthys
2024-12-04 12:46:091ec28f3f19bf173c69b3a3a16ecf178117407b517d7f4f57a6cf1a9b15fbe915lnkRhadamanthys
2024-12-04 12:46:0946d1b27aa5c040327d90c5d9044fceef8825572906065a97d61def0cd3b49a8blnkRhadamanthys
2024-12-04 12:45:1379755198eaa0d89aef549ed561d7a49c488055f20b25aeb5c3373379498d763eexe Adware.InstallCore
2024-12-04 12:45:13a9ce2c8a98a02f9f90bb4b649a34a5decc294c60f66c2365cd06d4f787343472exeRhadamanthys
2024-12-04 12:45:12d0f631f6269c14fe7622f4a1085f99e6bfd235942ce57715914ee4a319484a55exeRhadamanthys
2024-12-04 12:45:12ac3a503e94f241344f10f178fe378ac1f945ccd71a88c575622d91b376e3b6ecexe  
2024-12-04 12:44:059926933a12076a75672d0f7053cdb83dca09ab42d9bb0d7b73d3562f7d62381dbatRhadamanthys
2024-12-04 12:44:05fee1f3875cc575f85ada4b58b2fb3fbc4f798314cc42fe6bb4be90ffce346fb6batRhadamanthys
2024-12-04 12:44:05ce14a62151a1ee9ff5c559a25a8fece37c550197827d853b97669c6c8ee19e67batRhadamanthys
2024-12-04 12:43:0582b067a5106de338e6c305589d4844fd0c20142e49c808aa182c9c789979046dlnkRhadamanthys
2024-12-04 12:42:068de3d851efc7e0d42da0ecbc656ab93362595101d30b36ce36b7d698cdd99cd0batRhadamanthys
2024-12-04 12:42:06c3427b813ad0c2e6563b844e6fc080a7f18ca62880e7f2119adaad4e278b1285exeRhadamanthys