URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gestionycobranzas.com
Domain registrar:Cnobin Information Technology -
Domain registration date:2024-10-25 14:28:15 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-08-22 19:53:10 UTC
Total malware sites :26
Online malware sites :3 (12%)
Offline Malware sites :23 (88%)
Newest active malware site :2025-08-22 19:56:18 UTC
Oldest active malware site :2025-08-22 19:56:10 UTC (Age: 9 months, 8 days, 9 hours, 54 minutes)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-22 19:53:18 178.16.54.253SBL683901AS202412 OMEGATECH-AS- NLyes
2025-11-20 14:49:53 44.211.14.38ec2-44-211-14-38.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-11-13 05:48:59 84.32.84.33Not listedAS47583 AS-HOSTINGER- LTno
2025-09-04 08:13:56 84.32.84.32Not listedAS47583 AS-HOSTINGER- LTno
2025-09-04 11:40:05 149.62.37.222Not listedAS47583 AS-HOSTINGER- BRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-26 05:40:30http://gestionycobranzas.com/1/ws.pngOffline abuse_ch
2025-08-26 05:40:14http://gestionycobranzas.com/3/tre.txtOfflinerev-base64-loader abuse_ch
2025-08-24 07:47:21https://gestionycobranzas.com/1/MSI1.pngOfflinestego JAMESWT_WT
2025-08-22 19:56:18http://gestionycobranzas.com/2/remmbuil.txtOnlineopendir rev-base64-loader Riordz
2025-08-22 19:56:17http://gestionycobranzas.com/1/m.txtOfflineopendir Riordz
2025-08-22 19:56:15http://gestionycobranzas.com/2/task.vbsbkOfflineopendir Riordz
2025-08-22 19:56:15http://gestionycobranzas.com/1/SBoFJAOfflineopendir Riordz
2025-08-22 19:56:12http://gestionycobranzas.com/1/n02.jpgOfflinejpg-base64-loader opendir Riordz
2025-08-22 19:56:12http://gestionycobranzas.com/1/n22.jpgOfflinejpg-base64-loader opendir Riordz
2025-08-22 19:56:11http://gestionycobranzas.com/1/ROX.txtOfflineopendir rev-base64-loader Riordz
2025-08-22 19:56:11http://gestionycobranzas.com/2/task.vbsOnlineopendir RemcosRAT ext Riordz
2025-08-22 19:56:11http://gestionycobranzas.com/1/optimized_MSI.pngOfflineopendir Riordz
2025-08-22 19:56:11http://gestionycobranzas.com/1/WwUCwx.txtOfflineopendir Riordz
2025-08-22 19:56:10http://gestionycobranzas.com/1/mOfflineopendir Riordz
2025-08-22 19:56:10http://gestionycobranzas.com/2/task.jsOnlineopendir RemcosRAT ext Riordz
2025-08-22 19:54:19http://gestionycobranzas.com/3/NIKfyWrGOfflineopendir Riordz
2025-08-22 19:54:15http://gestionycobranzas.com/3/NxzvSZwyKOfflineopendir Riordz
2025-08-22 19:54:11http://gestionycobranzas.com/3/NKGKTO.txtOfflineopendir Riordz
2025-08-22 19:54:11http://gestionycobranzas.com/3/eMDGPBrDNOfflineopendir Riordz
2025-08-22 19:54:10http://gestionycobranzas.com/3/YRwmNxJi.txtOfflineopendir Riordz
2025-08-22 19:54:09http://gestionycobranzas.com/3/mXyMDIOfflineopendir Riordz
2025-08-22 19:54:09http://gestionycobranzas.com/3/vjzyQeREOfflineopendir Riordz
2025-08-22 19:54:09http://gestionycobranzas.com/3/salvador.exeOfflineopendir xworm Riordz
2025-08-22 19:54:09http://gestionycobranzas.com/3/SbkiaPRE.txtOfflineopendir Riordz
2025-08-22 19:54:08http://gestionycobranzas.com/3/ASPkoaO.txtOfflineopendir Riordz
2025-08-22 19:53:18http://gestionycobranzas.com/3/IPeYvuzkr.txtOfflineopendir Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-27 13:50:581232b4d0263b92835dbdef759d51c25e9fbec8743b6cb7fcb1916ac8491ce7f5unknown  
2026-05-27 13:00:23067beb9d7703d7dd66b960d946745e77006236931bf75e43bc3d2d157374109eunknown  
2026-05-26 17:45:08a931338ce349a84428c5257e7b96df8e659f3755bb292d5a48ca7697fbc3e25eunknown  
2026-05-26 14:05:395208a7566c915ad491d5aba908ffc98c37a5dd1558d60c694d4061793f8affedunknown  
2026-05-22 18:48:547b2b1e7a1ae484a23869c289ed8fe4082d8924b54efc97a27c73b76a51689880unknown  
2026-05-22 13:42:3223afbf9e324dc8b89896484af3da23ac5968e3fc2386053c55185d569774efb9unknown  
2026-05-19 15:33:264e2e8e0a8b684320c425999d2ee4a19a1a0f8e216c4a1c8f9a255f421f224ca2unknown  
2026-05-19 13:06:183c8af6dd35984f319eabc9237ba5d729aaf68ce86d8917f2302258096729b2c6unknown  
2026-05-13 15:29:285aa47d9abc41ca91399c2e1100db7bf49ee2857af2b021651b43da96c520063eunknown  
2026-05-13 13:49:451eda3589ec3fd471459c490d1a12d5108adbb4a0ae3c1adc1164d7b8669d7276unknown  
2026-05-12 19:14:44c3c7ece914139afb8189e5d842ad0d176171a74cf5b7221e16e22abb2e5a698funknown  
2026-05-12 18:49:227048a3e81dbc53e3afab91dceb3379ab03adfdaf4c0c8ff0534cd2f1f824a0d0unknown  
2026-05-11 19:28:067b38a81f8d06068340fd3b109be0ec5f8e87012c0f0090e9c4c86fcca20957c0unknown  
2026-05-11 18:57:34de5843a336930b53f23254277d54c4eeee609d59dd4eee8a2826b11c1034a60dunknown  
2026-05-08 14:07:2447ecd46c91d74a8d6467c7e4d6a038e9d5f959007b341e089c97589f31b25970js 
2026-01-26 14:28:430c7e13ddbeaa7e1ff1433439e632054b3061fecdf6d2437dc32a2dec2782923ejs RemcosRAT
2026-01-22 01:09:07ffc93f07c85d1fd0745093caac3b51f0d1df959aa4f483230ace089872129842js RemcosRAT
2025-11-13 02:57:370fea82f8fc3080d40ec9fd86a161f5011cd2f3efad982495866fa06d3299368ajs  
2025-09-04 07:59:576d401c709dd2a40e41f124164168f994dc9996a68025bda2df2f224ccab1908ajs 
2025-08-28 02:25:0860ade6262db0b1603755ece3ef0a64c35c8f5ef6df46ff42da5c0fd72cc08a37unknown  
2025-08-27 19:54:3674c1c627c31397e518687493b8a5af14b839decdb3227810335967cdd4697cactxt RemcosRAT
2025-08-27 19:47:09b87150092f1670db17050a71ba068b4515d42b104cafae4be5d76a7934674d0ejs RemcosRAT
2025-08-27 14:35:10045d2444fe26511003ddfb15e92697fb6f0278754817448d12525d65e75f1fdctxtRemcosRAT
2025-08-27 14:02:51cfa5264d2592a1fe11fed0d39d463cd1303eb428506125cb6c180a0e4c20caf0jsRemcosRAT
2025-08-26 20:43:57770b35baa103302f231c6be89e96d55294801a04aee02693842aa745f6dce621txtRemcosRAT
2025-08-26 19:38:050f18a22d54319e113ae30f9f3bd14fdd3c243924e8b8143692952cce72ecf09fjsRemcosRAT
2025-08-26 05:40:3008a5d0d8ec398acc707bb26cb3d8ee2187f8c33a3cbdee641262cfc3aed1e91dunknown  
2025-08-26 05:40:13e557e3620dc724d8ad07e965dd26ecaa875e82c66bd9a8c7c482e2333ede2547txt  
2025-08-25 20:40:3287fcbd1f67359062e18c02f3a27bc8e192cf771819fd929cc8a96d884cf35f5fjsRemcosRAT
2025-08-25 20:23:245867427e2a69435285a061f4cc882429558b4f7a2c0569219e74fdb7d68ec877txtRemcosRAT
2025-08-25 14:39:327fe73890d1d759d4787546b61a296d3ad97d72ce95e5cc60f4c67fc68b371ed4jsRemcosRAT
2025-08-25 14:16:5583b9a76e6395ef08f25390d50a3e1ca363b320325b4f978a8abde5ca2150c436txt RemcosRAT
2025-08-24 07:47:1908a5d0d8ec398acc707bb26cb3d8ee2187f8c33a3cbdee641262cfc3aed1e91dunknown  
2025-08-23 20:17:50a763e16f8a534c9c9ccd5ffca2c48fffa70ca02122983885922d3ad0a1063deftxt 
2025-08-23 14:31:38b637ac96e93426857c85f0c7e98ed3b07b8ea8a7444534292137c6e2a632a7adjs  
2025-08-23 02:37:4270c230ca07e38d63582972c78a69a738f1ba6165f273b220c98d92fc06e047e6txt  
2025-08-23 01:59:19bae68d68082dd0febfd2a881346d9d14e7927f56093449a679cafeb3050d4ca4txt  
2025-08-23 01:20:3923109caeac3e34cdd16544a231d63d98e5df78b3c95543382808d530abd8a77etxt  
2025-08-22 19:56:181e4e0ee7880e17947cf6cdf024980c2c39bada0bb4bf457f68a0ecb4ec7b3f70txt  
2025-08-22 19:56:172de6406306458bbe79dff19204ed4f6fd43cbaf67e6873f9bf0bc9aa142f2867txt  
2025-08-22 19:56:15d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:56:12a7c900e48ebecdac18b2679dafc25236c88f0ed644d335997d4d4b4b19a5fd63jpg  
2025-08-22 19:56:12a7c900e48ebecdac18b2679dafc25236c88f0ed644d335997d4d4b4b19a5fd63jpg  
2025-08-22 19:56:11ed971bcfc5a9eebfbecc9aab050ffb9e6d9cfe38a72fd6f74cfec39cbd31475ftxtRemcosRAT
2025-08-22 19:56:11ec4909738ec8c8729a34582c8fdb8131a28eb0eeaab81a0066b884affce55e24unknown  
2025-08-22 19:56:11c31288cbf912b338dee0681791eabfaced23f5819365f43fefc77d9a646b1a24txt  
2025-08-22 19:56:114a27d34ed9b1035946da8548d26177a051c62ceaffc266a8a6eea684d7e8aab6txt  
2025-08-22 19:56:10d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:56:10b5db53c35044419ae5c13ecbb481b063a418cb08623e34cd877c318fc10134dfjs  
2025-08-22 19:54:19d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:54:15d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:54:11d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:54:102de6406306458bbe79dff19204ed4f6fd43cbaf67e6873f9bf0bc9aa142f2867txt  
2025-08-22 19:54:0966cc8ae0a0de5618f04bae1d2321edbb92d6dd296a7b879b5618af28d2741fa1exeXWorm
2025-08-22 19:54:09d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:54:09d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fdexe  
2025-08-22 19:54:0816fcb98453d6a4d24dc2e3cda22a3ac813e5345ee9135402ddc99cae8f02295ctxt  
2025-08-22 19:53:1716fcb98453d6a4d24dc2e3cda22a3ac813e5345ee9135402ddc99cae8f02295ctxt