URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-10 20:04:55 | 89.35.77.26 | cp2-26.activ.net | Not listed | AS49302 ACTIVENET-AS | RO | yes |
| 2025-02-08 17:28:03 | 89.35.77.25 | cp2.activ.net | Not listed | AS49302 ACTIVENET-AS | RO | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-02-08 17:28:28 | https://ilimed.ro/ufcu/streamingwealth/ssl.jpg | Offline | ascii Encoded opendir rat RemcosRAT | |
| 2025-02-08 17:28:27 | https://ilimed.ro/ufcu/streamingwealth/onedrive... | Offline | ascii AsyncRAT | |
| 2025-02-08 17:28:26 | https://ilimed.ro/ufcu/streamingwealth/backuppl... | Offline | ascii Encoded opendir RemcosRAT | |
| 2025-02-08 17:28:26 | https://ilimed.ro/ufcu/streamingwealth/onetribe... | Offline | ascii Encoded Formbook | |
| 2025-02-08 17:28:03 | https://ilimed.ro/ufcu/streamingwealth/Onedrive... | Offline | ascii opendir vbs | |
| 2025-02-08 17:28:03 | https://ilimed.ro/ufcu/streamingwealth/onetribe... | Offline | ascii opendir vbs |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-02-08 17:28:28 | 177e7f2f432de2114b03726840b940a6d76957f28b6b432dad074d4ca1efd073 | txt | RemcosRAT | |
| 2025-02-08 17:28:27 | dfa3750a546f39d76a6390d564e2ba9e376c81dfa935b1397d13199663b157b5 | txt | AsyncRAT | |
| 2025-02-08 17:28:26 | bb745b973d30867bec8f04e7176c1b6d5799ad5c0e259d00c1ac421be77948ab | txt | RemcosRAT | |
| 2025-02-08 17:28:26 | 92c031688fedd28a8261263a7a3a8dcba7d581d925d63a1e78ed087540f27d7c | txt | Formbook |
RO