URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: eurex.ps
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-03-18 07:18:03 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-18 07:18:05 192.185.155.188192-185-155-188.unifiedlayer.comNot listedAS19871 NETWORK-SOLUTIONS-HOSTING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-19 15:07:13http://eurex.ps/vespa/betnal.exeOfflineexe RemcosRAT ext abuse_ch
2021-03-19 15:06:56http://eurex.ps/vespa/regsvcxm.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-03-19 15:06:52http://eurex.ps/vespa/mancy.exeOfflineexe RemcosRAT ext abuse_ch
2021-03-18 19:01:04http://eurex.ps/bomx/abnol.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-18 18:54:04http://eurex.ps/bomx/mcnam.exeOfflineexe opendir RemcosRAT ext abuse_ch
2021-03-18 18:51:05http://eurex.ps/bomx/ndena.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-18 18:51:05http://eurex.ps/bomx/mbena.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-18 18:51:04http://eurex.ps/bomx/doglox.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-18 09:42:05http://eurex.ps/english/okl/xckex.exeOfflineAgentTesla ext exe zbetcheckin
2021-03-18 07:18:09http://eurex.ps/bomx/4IM6UdbDirEU0hR.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-03-18 07:18:05http://eurex.ps/bomx/abman.exeOfflineAgentTesla ext exe opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-03-19 20:39:4890089cb8df29d4d8169975ce0545f298aa830376a12a097722ec7f8ef9317760exeAgentTesla
2021-03-19 15:07:136b6d820ce1c8df1c795e938995133201a5c75ad3989cd51568323b671ecf8109exeRemcosRAT
2021-03-19 15:06:564646cdc649c3d1a2c68fdf4f40f1006b55ed3d30bbe0e07b2e27ac91edcdba21exeSnakeKeylogger
2021-03-19 15:06:52ead243034e5816a6899ee5a8aa2582c58824bbb06967a25ca2811f83457c9b46exeRemcosRAT
2021-03-19 13:40:421e610d9e5c54f5f5ecece3d88d3d1787fca89cc1975f56cc352e4963e977c3cbexeSnakeKeylogger
2021-03-18 19:01:048a3e6eba5ffc2a598f2f7d4b2c1a73c845f8c1660ed47c0cdc1df48844f7f1ebexeAgentTesla
2021-03-18 18:54:0438e003f280936ad6c0cacd7a57e6864de55b11058f5c0d45f8b3e42313bfdf84exeRemcosRAT
2021-03-18 18:51:054c83b9a705090f3edd4f8f1322ec609b7a04d59d03b390681c3708c61341eb1aexeAgentTesla
2021-03-18 18:51:05aa128e8000ef9197eed67a5b6f27454e0c1b1878ed7546394fde472d42836eb9exeAgentTesla
2021-03-18 18:51:0483bf33f59a2317bc1dd4457798cae79e2d607d511cf12c3c0cff36886fe20d19exeAgentTesla
2021-03-18 09:42:052879f1773178be4e0cfea138616e306939389d4d5d55ef94269cda0998cd3244exe AgentTesla
2021-03-18 08:33:22993ff110af136acf1200dd8ad51a4b284a0e2086efffce49d6e3fd759e607420exeSnakeKeylogger
2021-03-18 08:27:599ecab8874967c53279d62d6fece35433adf4d296ac81d255e7ea61bea88d399aexeAgentTesla
2021-03-18 07:18:098bf700d82610f1f93068727641d03f699d81b35a8d906f05d00f1853f8be78c0exeSnakeKeylogger
2021-03-18 07:18:041c7866cbbb7548f836766e024e6bf9d4d300493b83dbeebdcba8b1deff8e35cbexeAgentTesla