URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 95.214.24.120
Firstseen:2022-08-30 13:01:03 UTC
Total malware sites :41
Online malware sites :0 (0%)
Offline Malware sites :41 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-08-30 13:01:03 95.214.24.120Not listedAS215873 tods-it- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-10 08:46:06http://95.214.24.120/C/fire.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:06http://95.214.24.120/C/john.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:06http://95.214.24.120/C/pa.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/babad.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/uzoo.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/ham.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/cool1.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/dbili.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/ugo.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/ezef.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/fineof.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/mrloga.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/jj.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/hamza.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/dikeaz.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/2.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:05http://95.214.24.120/C/ec.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:04http://95.214.24.120/C/yung2.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:04http://95.214.24.120/C/dbili2.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:04http://95.214.24.120/C/COOL2.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:46:04http://95.214.24.120/C/fineboy.txtOfflineascii Encoded opendir abuse_ch
2022-10-10 08:18:04http://95.214.24.120/C/DLL.txtOfflineascii Encoded opendir rat RemcosRAT ext abuse_ch
2022-10-10 08:17:04http://95.214.24.120/C/HUZ.txtOfflineascii Encoded rat RemcosRAT ext abuse_ch
2022-09-11 01:08:04http://95.214.24.120/vect/yytdsghghdfb.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-09-01 10:28:04http://95.214.24.120/vect/VBXCBCXVHGS.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-09-01 10:26:04http://95.214.24.120/vect/QQBVBZCHGJHSF.exeOfflineAgentTesla ext exe abuse_ch
2022-09-01 02:42:04http://95.214.24.120/vect/VBCXVGHFDJ.exeOffline32 exe Formbook ext zbetcheckin
2022-08-31 08:27:04http://95.214.24.120/vect/NBXCJHDSD.exeOffline32 exe Formbook ext zbetcheckin
2022-08-31 07:13:04http://95.214.24.120/vect/DUTRFGbNG.exeOfflineexe Formbook ext opendir abuse_ch
2022-08-31 07:13:04http://95.214.24.120/vect/dave.txtOfflineascii Encoded opendir abuse_ch
2022-08-31 07:13:04http://95.214.24.120/vect/DLLL.txtOfflineascii Encoded opendir abuse_ch
2022-08-31 07:13:04http://95.214.24.120/vect/BGTHPNHv.exeOfflineexe opendir RemcosRAT ext abuse_ch
2022-08-31 07:13:04http://95.214.24.120/vect/VXGFHDHHFG.exeOfflineexe opendir RemcosRAT ext abuse_ch
2022-08-31 07:13:04http://95.214.24.120/vect/BNCHHVGHJHJK.exeOfflineexe Formbook ext opendir abuse_ch
2022-08-31 07:13:03http://95.214.24.120/vect/QQPPLOGGCDH.exeOfflineexe Formbook ext opendir abuse_ch
2022-08-31 07:13:03http://95.214.24.120/vect/NBCXHGGHJDF.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-08-31 07:13:03http://95.214.24.120/vect/davex.txtOfflineascii Encoded opendir abuse_ch
2022-08-31 07:10:05http://95.214.24.120/vect/NBCHGDGD.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-08-31 00:14:04http://95.214.24.120/vect/WTRGHXBHJX.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-08-31 00:13:04http://95.214.24.120/vect/XXFHFHFHD.exeOffline32 exe Formbook ext zbetcheckin
2022-08-30 13:01:03http://95.214.24.120/vect/VNBCHJJDS.exeOfflineexe Loki ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-10 08:46:06d3416937c321e3419423a2fa65401d3cd6587105542fbd041d548c875d37e456txt  
2022-10-10 08:46:062b40bbe12da2ac6007954562b6410c9befe32b825cee75b619f6b58ee194e7fdtxt  
2022-10-10 08:46:065cd984999bd8247605963dfaa79f5e20a7c9322bfe6545dac895efaf52a62b65txt  
2022-10-10 08:46:050b0b096a00937aad2e8328151248ff5debdcaaf6a4e8cf13c1ad11a7cd719982txt  
2022-10-10 08:46:05de288a62f3ea95d850589ea2610d01bcf9323c68e905fe9df54ab084dd5c29d1txt  
2022-10-10 08:46:05528f5b7784f9dfa744ad6dec27cee34803b807afe1bedd1a29bd83dfd7e06851txt  
2022-10-10 08:46:05bbf07f5708d3325a1da73a180830fda474955ee1af090d9989ad826c4aff9504txt  
2022-10-10 08:46:0525ace9ec9340b81313e3bbae01125f9098d5e2be55a51050983ec9a632d03ba6txt  
2022-10-10 08:46:0563fc53b25d5477325abf9e8502fce8837b07df40804365a7040c08b0dd84f23ctxt  
2022-10-10 08:46:05313b54a0d3afbb4a39efa4639d46a3fdd48ec21b90a8200bfeffe4c73983f9c7txt  
2022-10-10 08:18:04bb18aa9ba1f006ab946450177cc831f09c84ca83700801b60129b3ece191a1betxt  
2022-10-10 08:17:043ec76a34ba05254b8884a6235e8c7485ee86ec2ec46ad98f03dfe753e6f97ff9txt  
2022-09-11 01:08:04e76cebc404b8a79e2ab806a3e501b9d2f7260ea1d12f804320c1130be205dff6exeRemcosRAT
2022-09-07 02:41:38b5d606d86246cd40903e8b84d48c34633cbc8189a824bb412b9a0aea0c7232cfexe  
2022-09-07 02:31:22f9d76905941238dcb8c1c30786fbad459fcc466de1409ff5b47571994f3328ffexe  
2022-09-01 19:34:504f2316b45197b7f4ed625123e43dd47056e026d2e6f79f47f7d2ccca2f012a49exeLoki
2022-09-01 10:28:04006854d4623003bf6b98110f8c8108d97d475055511bd9d222b8d3bc6f39f8dcexeAgentTesla
2022-09-01 10:26:041f6e1758b123080556a5ee96779d9ef63f54f9af1d07d8a3cc8cff39c636b12bexeAgentTesla
2022-09-01 02:42:0415eb688bffed96b0b324724e48b258dc6c6deb76d71310b26b01e1e12f26108cexeFormbook
2022-08-31 08:27:04b47cf0eaed7e3798e77eaf01aac5783f2c03f7db7802a5215523d4ccdc631bc5exeFormbook
2022-08-31 07:13:0486369d60c9f6b68598952379aaa9b0d3b7af84294b4aece68359552287d3456fexeFormbook
2022-08-31 07:13:04fadbc6f814008e75bff67f36923f9e2fa2faf5312ac8243e80236f57a17e12c1exeRemcosRAT
2022-08-31 07:13:040065495640ca573d1528ef14bfc33d30e1a5542b95d05601fb1fc49de4bb64f7exeFormbook
2022-08-31 07:13:045baaa1bb5e6b51d0f7cad61124d33048c61376a2194ee68f7b0ee57697cd53a4exeRemcosRAT
2022-08-31 07:13:04bd84bdb9d0b812c2bd9d130f302e660ff1dee4f57c43d2d81c6a8b9efbf093e4txt  
2022-08-31 07:13:049b73b7a3a2378e5e8d53919211b4168ca53c43b4026cc42b8d64be0bc4c0769ctxt 
2022-08-31 07:13:032f177a146603287dc4b1c68c16495a01f87d5f0e60f84880d9b875da8ffbdee3exeFormbook
2022-08-31 07:13:03277fce3b2d847d9d39886066c99013feb62399e5cb0fedbea2ce197f2c158157exeAgentTesla
2022-08-31 07:10:05d534bb2cf15eb0efe9465b1b7cfddd2a34087210f11539b7fc4f2dd9e79a40f8exeAgentTesla
2022-08-31 00:14:044e24f18c609d04ba55264362e311e7536eda95872bf42a3327b7970f2b8eaacbexeRemcosRAT
2022-08-31 00:13:047d850c7483817ae91c6b6dde59c22141b754d04ec2e0985ffcd85b08f2e9ae58exeFormbook