URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: hbws.cc
Domain registrar:NameSilo -
Domain registration date:2024-11-26 09:46:09 UTC
Spamhaus DBL :Botnet C&C domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-05-21 08:20:05 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-28 12:42:55 147.124.215.99Not listedAS396073 MAJESTIC-HOSTING-01- USyes
2025-07-20 20:35:10 185.208.156.168perfectsemplegas.deSBL640646AS42624 swissnetwork02- SCno
2025-06-15 04:38:45 185.208.158.17casabautiquekw.comSBL640646AS42624 swissnetwork02- USno
2025-05-29 11:43:54 91.219.150.209hbws.ccSBL655148AS56694 SmartApe- RUno
2025-05-21 08:20:12 91.219.151.65s1223356.smartape-vps.comNot listedAS56694 SmartApe- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-07-15 13:10:07http://hbws.cc/RRC_204_LrrpgyfrayjOffline abuse_ch
2025-07-12 18:03:11https://hbws.cc/RRC_200_CgdqgnvkfcpOfflineascii DBatLoader ext Encoded ModiLoader ext rat RemcosRAT ext abuse_ch
2025-07-12 06:15:08http://hbws.cc/RRC_154_BwesftmkgmzOfflineascii Encoded rat RemcosRAT ext abuse_ch
2025-06-28 15:21:08https://hbws.cc/king.cmdOfflineascii Encoded RemcosRAT ext abuse_ch
2025-06-28 15:16:09https://hbws.cc/grace.cmdOfflineascii Encoded rat RemcosRAT ext abuse_ch
2025-05-24 23:01:37http://hbws.cc/scri.txtOffline DaveLikesMalwre
2025-05-21 08:20:12https://hbws.cc/king.txtOfflineascii Encoded rat RemcosRAT ext rev-base64-loader abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-07-22 16:20:053c4442c45a6bb6b89ae1d14d577a9ab3cd8814f612980b7cccd8f8f0cbfbe34dexe RemcosRAT
2025-07-20 23:40:148c9084133b3d9cf46b8f3b9447c38f4e0fe509c299f496ea9a755baaf4aac467exeRemcosRAT
2025-07-15 00:01:52238b2e718bf1102c195b808c4429c1f603701a941df4dd4dece36c5913acd00cunknown RemcosRAT
2025-07-14 12:05:057385f9e5ef6a5310ab17a2c335f4554204e2c17c942fb27c3447bece6d3adbf9exe RemcosRAT
2025-07-12 18:03:11fbc7b5c465ba4349ab62a6c58de328c7e1638d30444996191f747e3758d58f93txt  
2025-07-12 06:15:08ee64c0f22a07acd49d2dbc46b12bc1d188ff563aba0c8623d6350882c8c40860txt  
2025-07-11 17:11:4470a92cdcd65bad4c5ed38adf340d5123944acde22d94c44df7ee8178f778d761batRemcosRAT
2025-07-10 00:13:01a35d3ab5f3c9cd7758b3732a800804fb1b08c02d2c049a1ed18ae11b0a63b397exe RemcosRAT
2025-07-08 17:04:419cfd04b42bb879d28a357c3317a555c6fe3b4c0e742af6665e5a8d99df0a06d3exe RemcosRAT
2025-07-06 10:48:5599801779f306c924520d43c82b9b0021362cdfd54aad90c58c63ae6d1137fef1exe RemcosRAT
2025-07-03 11:28:45c0ce6d7088382932c56ce3661ca90d967381b5abc7424769fe4d11047b20fb40exe RemcosRAT
2025-07-02 23:25:09847586ed3d30609e4fe7afd5805e08b7f567e563a25375fdf660dd86a219f24fexe RemcosRAT
2025-07-01 23:29:3047e617afb46967a44544313425c6c3d84d49758554feb1a7258149f2a3a23d2eexeRemcosRAT
2025-06-30 11:11:377e56f589e9f4b4f3bfea45261d0f3d50938aa33e703ce35d9edc55b3ca4fccc3exe RemcosRAT
2025-05-21 08:20:11fd7722b20acd32ca84b6720c62801c0ae72df94a6265b6907fd9915350e32783txt RemcosRAT