URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-08-29 18:32:09 | 195.123.225.67 | vds1198068.hosted-by-itldc.com | Not listed | AS59729 ITL-BG | BG | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-08-30 06:20:10 | http://royalcollections.buzz/jameszx.exe | Offline | AveMariaRAT | |
| 2023-08-30 06:20:08 | http://royalcollections.buzz/chungzx.exe | Offline | exe rat RemcosRAT | |
| 2023-08-29 18:32:09 | http://royalcollections.buzz/ghostzx.exe | Offline | exe Formbook |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-08-30 06:20:10 | 9af290003182dbbb2097e6442f8321bda52b75f19415a48d9072bdce9596e6ef | exe | AveMariaRAT | |
| 2023-08-30 06:20:08 | 0cf19ee17510d2a5fc76fd37c7f662ba08000697db304795fc26c936e952cc8e | exe | RemcosRAT | |
| 2023-08-29 18:32:07 | c0545f16fbbecef4ff1983c05e620651f24c48d3debaf525fd3e057ef688fae4 | exe | Formbook |

BG