URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | courtyardhealthcare.com |
|---|---|
| Domain registrar: | Namecheap ![]() |
| Domain registration date: | 2009-04-21 21:45:04 UTC |
| Spamhaus DBL : | Phishing domain |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Not blocked |
| Cloudflare : | Not blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Blocked |
| Firstseen: | 2025-03-20 12:31:08 UTC |
| Total malware sites : | 5 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 5 (100%) |
| A record(s) observed : | 1 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-03-20 12:31:09 | 5.181.157.225 | no-rdns.mivocloud.com | Not listed | AS39798 MivoCloud | MD | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-03-21 08:08:13 | https://courtyardhealthcare.com/PD/TcslA.exe | Offline | exe | Anonymous |
| 2025-03-21 07:57:11 | https://courtyardhealthcare.com/feb/xpmg.exe | Offline | exe | Anonymous |
| 2025-03-21 07:57:10 | https://courtyardhealthcare.com/March/Edgevieww... | Offline | exe RemcosRAT | Anonymous |
| 2025-03-21 07:57:04 | https://courtyardhealthcare.com/March/xpmg%20%2... | Offline | exe | Anonymous |
| 2025-03-20 12:31:10 | https://courtyardhealthcare.com/AAV/compited.txt | Offline | ClickFix FakeCaptcha |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-03-21 08:08:12 | e992fc3ca6af16bde2b30ce5e816061846a0bc4b567bea5f6a921bb7db5c06d5 | exe | ||
| 2025-03-21 07:57:24 | 666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e | exe | ||
| 2025-03-21 07:57:11 | 666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e | exe | ||
| 2025-03-21 07:57:09 | 63c6397f3431639ee54b68cf2837024862d699ccdc41cddf64058be91ae0b87e | exe | RemcosRAT |

MD