URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: respaldo2.duckdns.org
Domain registrar:Gandi -
Domain registration date:2013-04-12 19:58:56 UTC
Abuse complaint sent?: Yes (2025-10-05 23:22:02 UTC to abuse{at}duckdns[dot]org)
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-12-17 08:41:04 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-03 14:51:40 158.94.209.243SBL686264AS214943 RAILNET- NLyes
2025-08-25 11:46:27 213.136.83.185m31185.contaboserver.netNot listedAS51167 CONTABO- FRno
2025-08-26 16:23:11 94.26.90.120SBL676377AS207043 DEDIK-IO- DEno
2025-08-13 21:40:47 213.136.81.72m30072.contaboserver.netNot listedAS51167 CONTABO- FRno
2025-06-16 23:36:44 45.82.251.235server.835Not listedAS209847 THE- CYno
2025-05-28 01:55:33 95.111.242.255Not listedAS51167 CONTABO- FRno
2024-12-17 08:41:13 209.105.248.135Not listedAS13354 ZC38-AS1- USno
2025-03-18 17:52:05 213.199.55.238m27238.contaboserver.netNot listedAS51167 CONTABO- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-05 23:21:28http://respaldo2.duckdns.org/scvhost.vbsOfflineduckdns opendir remcos ext RemcosRAT ext Riordz
2025-10-05 23:21:10http://respaldo2.duckdns.org/proceso.vbsOfflineduckdns opendir remcos ext RemcosRAT ext Riordz
2025-04-12 18:48:20http://respaldo2.duckdns.org/sostener1.vbsOfflineopendir ua-wget vbs DaveLikesMalwre
2025-04-12 18:48:14http://respaldo2.duckdns.org/svchost.vbsOfflineAsyncRAT ext opendir ua-wget vbs DaveLikesMalwre
2024-12-17 08:41:13http://respaldo2.duckdns.org/sostener.vbsOfflineAsyncRAT ext abus3reports