URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rtost.duckdns.org
Domain registrar:Gandi -
Domain registration date:2013-04-12 19:58:56 UTC
Abuse complaint sent?: Yes (2025-06-07 21:30:00 UTC to abuse{at}duckdns[dot]org)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-06-07 21:26:06 UTC
Total malware sites :58
Online malware sites :2 (3%)
Offline Malware sites :56 (97%)
Newest active malware site :2025-08-25 11:25:19 UTC
Oldest active malware site :2025-08-14 08:51:34 UTC (Age: 9 months, 20 days, 8 hours, 49 minutes)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-25 19:26:00 192.169.69.26sinkhole.hyas.comNot listedAS27323 SERVERSTADIUM- USyes
2025-08-15 11:28:14 162.240.80.146162-240-80-146.unifiedlayer.comNot listedAS46606 UNIFIEDLAYER-AS-1- USno
2025-08-14 14:12:02 45.134.140.234unn-45-134-140-234.datapacket.comNot listedAS212238 CDNEXT- USno
2025-06-08 03:18:01 168.100.160.208168.100.160.208.galaxy.cosmic.globalNot listedAS26863 GAMESERVERKINGS- USno
2025-08-09 23:42:19 1.1.1.1one.one.one.oneNot listedAS13335 CLOUDFLARENETn/ano
2025-07-10 11:07:03 8.8.8.8dns.googleNot listedAS15169 GOOGLE- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-25 11:25:24http://rtost.duckdns.org/target/handshake.phpOffline JAMESWT_WT
2025-08-25 11:25:22http://rtost.duckdns.org/mimicr/winlogon.comOffline JAMESWT_WT
2025-08-25 11:25:22http://rtost.duckdns.org/mimicr/Launcher.exeOffline JAMESWT_WT
2025-08-25 11:25:19http://rtost.duckdns.org/mimicr/WinUpdatehan.exeOffline JAMESWT_WT
2025-08-25 11:25:19http://rtost.duckdns.org/mimicr/WinUpdate2han.exeOffline JAMESWT_WT
2025-08-25 11:25:19http://rtost.duckdns.org/mimicr/mimicr5.7.rarOffline JAMESWT_WT
2025-08-25 11:25:19http://rtost.duckdns.org/mimicr/LogonUi.exeOfflineCoinMiner JAMESWT_WT
2025-08-25 11:25:19http://rtost.duckdns.org/mimicr/Launcherhmd.exeOffline JAMESWT_WT
2025-08-25 11:25:18http://rtost.duckdns.org/mimicr/tokenborkerdll.exeOffline JAMESWT_WT
2025-08-25 11:25:17http://rtost.duckdns.org/mimicr/TokenBorkerCFG.exeOffline JAMESWT_WT
2025-08-25 11:25:13http://rtost.duckdns.org/mimicr/WinUpdatehmd.exeOffline JAMESWT_WT
2025-08-25 11:25:12http://rtost.duckdns.org/mimicr/WinUpdate2hmd.exeOffline JAMESWT_WT
2025-08-25 11:25:11http://rtost.duckdns.org/mimicr/RuntimeBorkerDl...Offline JAMESWT_WT
2025-08-25 11:25:11http://rtost.duckdns.org/mimicr/NEWVER.exeOffline JAMESWT_WT
2025-08-25 11:25:11http://rtost.duckdns.org/mimicr/launcher2hmd.exeOffline JAMESWT_WT
2025-08-25 11:25:09http://rtost.duckdns.org/mimicr/confhan.txtzOffline JAMESWT_WT
2025-08-25 11:25:09http://rtost.duckdns.org/mimicr/WinUpdateOffline JAMESWT_WT
2025-08-25 11:25:08http://rtost.duckdns.org/mimicr/WinUpdateMmr.exeOffline JAMESWT_WT
2025-08-25 11:24:20http://rtost.duckdns.org/mimicr/moi(old).ps1Offline JAMESWT_WT
2025-08-25 11:24:16http://rtost.duckdns.org/mimicr/moi(old).batOffline JAMESWT_WT
2025-08-24 07:47:07http://rtost.duckdns.org/mimicr/WinUpdate.exeOffline JAMESWT_WT
2025-08-14 08:51:36http://rtost.duckdns.org/mimicr/stel1.exeOffline JAMESWT_WT
2025-08-14 08:51:32http://rtost.duckdns.org/mimicr/Akee.rarOffline JAMESWT_WT
2025-08-14 08:51:31http://rtost.duckdns.org/mimicr/wallet-clean-ch...Offline JAMESWT_WT
2025-08-14 08:51:31http://rtost.duckdns.org/mimicr/Akee.exeOffline JAMESWT_WT
2025-08-14 08:51:30http://rtost.duckdns.org/mimicr/Ak123ee.rarOffline JAMESWT_WT
2025-08-14 08:51:28http://rtost.duckdns.org/mimicr/WinRing0x64.sysOffline JAMESWT_WT
2025-08-14 08:51:28http://rtost.duckdns.org/mimicr/Akee2.exeOffline JAMESWT_WT
2025-08-14 08:51:28http://rtost.duckdns.org/mimicr/Launcherhan.exeOffline JAMESWT_WT
2025-08-14 08:51:26http://rtost.duckdns.org/mimicr/RuntimeBorkerha...Offline JAMESWT_WT
2025-08-14 08:51:26http://rtost.duckdns.org/mimicr/confhmd.txtOffline JAMESWT_WT
2025-08-14 08:51:23http://rtost.duckdns.org/mimicr/moi2.batOffline JAMESWT_WT
2025-08-14 08:51:23http://rtost.duckdns.org/mimicr/Launcher2han.exeOffline JAMESWT_WT
2025-08-14 08:51:22http://rtost.duckdns.org/mimicr/anyinstall.batOffline JAMESWT_WT
2025-08-14 08:51:21http://rtost.duckdns.org/mimicr/RuntimeBorker2h...Offline JAMESWT_WT
2025-08-14 08:51:20http://rtost.duckdns.org/mimicr/RuntimeBorkerhm...Offline JAMESWT_WT
2025-08-14 08:51:18http://rtost.duckdns.org/mimicr/moi2han.batOffline JAMESWT_WT
2025-08-14 08:51:17http://rtost.duckdns.org/mimicr/moishan.ps1Offline JAMESWT_WT
2025-08-14 08:51:17http://rtost.duckdns.org/mimicr/netWork64.exeOffline JAMESWT_WT
2025-08-14 08:51:17http://rtost.duckdns.org/mimicr/AnydeskBackdoor...OfflineAnyDesk JAMESWT_WT
2025-08-14 08:51:16http://rtost.duckdns.org/mimicr/conf2han%20-%20...Offline JAMESWT_WT
2025-08-14 08:51:16http://rtost.duckdns.org/mimicr/onsk.exeOffline JAMESWT_WT
2025-08-14 08:51:16http://rtost.duckdns.org/mimicr/moi%28old%29.batOffline JAMESWT_WT
2025-08-14 08:51:14http://rtost.duckdns.org/mimicr/Akee.ps1OfflineDEU geofenced powershell script JAMESWT_WT
2025-08-14 08:51:14http://rtost.duckdns.org/mimicr/moi%28old%29.ps1Offline JAMESWT_WT
2025-08-14 08:51:13http://rtost.duckdns.org/mimicr/conf2han.txtOffline JAMESWT_WT
2025-08-14 08:51:13http://rtost.duckdns.org/mimicr/conf2hmd.txtOffline JAMESWT_WT
2025-08-14 08:51:12http://rtost.duckdns.org/mimicr/moi.ps1Offline JAMESWT_WT
2025-08-14 08:51:12http://rtost.duckdns.org/mimicr/ExeFixer.regOffline JAMESWT_WT
2025-08-14 08:51:12http://rtost.duckdns.org/mimicr/mois.ps1Offline JAMESWT_WT
2025-07-12 06:45:24http://rtost.duckdns.org/mimicr/stel.exeOfflineexe abuse_ch
2025-07-12 06:45:20http://rtost.duckdns.org/mimicr/gcide.exeOfflineexe abuse_ch
2025-07-12 06:45:11http://rtost.duckdns.org/mimicr/clper.exeOfflineexe abuse_ch
2025-06-07 21:26:16http://rtost.duckdns.org/mimicr/moi.exeOfflineexe Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-25 14:23:4088f7faa11b036eb9f5083d592201a39609b06cf0335bc4ab370a78bdc3e85830exe 
2025-08-25 13:56:254a8e2ca5f5a65c73e3e910d06b5760ab18177e94d0da8f0c7ec22caee404ac87exe 
2025-08-25 11:25:224d1e682b22632faafe730584ce724bb60ad384a2b6974fe5f72e9df76b344bbeexe 
2025-08-25 11:25:2205abec9c66e23791ab1225bf81e829aca5ad215cee739a11d17883b1c20dfd91exe 
2025-08-25 11:25:1938dcde77f6a4b30bb75395d693cbc1c621d894737a178c1c1a18aa42f95f732eexe 
2025-08-25 11:25:19735c82b56c6561b6b101ad6dbaf402e462bae4e518df071cd637bb9a8065772fexe 
2025-08-25 11:25:19914a2432986a94ea4727fadc1e9d216119c09b2628a320108db387849e7bbff4exe 
2025-08-25 11:25:1972d3433222e9aad5bf48aee72ebb62a5575b066fadea883add2af9e79cbc1977exe 
2025-08-25 11:25:19e0cffe40c3b4cce567f25ac39b33eefd0dbd3cab701d3c52be21697675950f3bexeCoinMiner
2025-08-25 11:25:195c681ec3347ba20e9fd1fb16d2d6d0a8249b6e504d9fde7dfac2b0ad4caabf9brar  
2025-08-25 11:25:184d1e682b22632faafe730584ce724bb60ad384a2b6974fe5f72e9df76b344bbeexe 
2025-08-25 11:25:1388f7faa11b036eb9f5083d592201a39609b06cf0335bc4ab370a78bdc3e85830exe 
2025-08-25 11:25:1172d3433222e9aad5bf48aee72ebb62a5575b066fadea883add2af9e79cbc1977exe 
2025-08-25 11:25:11778999ec7de998a62cf77f6b0ac379915e31093c4753c00629bfd51160fb2150exe 
2025-08-25 11:24:2059d3b03ddb21c222af31e8237623ccc4777b107be7cad9e7e2119bbbaf49a8e3txt 
2025-08-25 11:24:16ce389d2cc91ef8d9ff8b063404658ed1386d0eabe19150e4d33ae21fb7f6f662bat  
2025-08-23 20:09:46896f271881e0f602d62ed8f69b960d579c0c5d38e22220e317b4fe2ad104a514json  
2025-08-23 19:28:31896f271881e0f602d62ed8f69b960d579c0c5d38e22220e317b4fe2ad104a514json  
2025-08-16 21:13:4459d3b03ddb21c222af31e8237623ccc4777b107be7cad9e7e2119bbbaf49a8e3txt 
2025-08-15 15:58:569af2bed13ecae054982d7e3a5d9ebd8c01a15ac4338b37ca0df28c78f27e11e5txt 
2025-08-15 13:40:2538b0b4df000d5e65d888b24778164fc43ba33e92e92ba716a46be8f1dc59acd6txt 
2025-08-15 13:23:4425b1d00184d3ea662130a8e1837690b18b45f153dac4df20aa8185edbb7ff2bbtxt 
2025-08-15 12:41:143c14a50b4c227b98732434c0a3d231d6f7b1e28ef8088ff7fcd87cad7e20bc81json  
2025-08-15 12:18:1587811f68ec70aba4dab61e6f40d5dd897470ff3152cc34e6fe8dcfa08b94b416txt 
2025-08-14 08:51:3655b9042319dfc7ab9c7401344c44a41a7a4f56f8893aad8129bb71a69bc98f0aexe  
2025-08-14 08:51:341821577409c35b2b9505ac833e246376cc68a8262972100444010b57226f0940exe  
2025-08-14 08:51:32dd4af79225cdca6df5e6f799a0a51b5d550bafbb317848b0997e0c2015ee5622rar  
2025-08-14 08:51:3149dcc857bc7ed84f2d3a396696e7ed4cfdd8a2512e05d01b717fb3139e5a45a5exe  
2025-08-14 08:51:310bdadbc5f5d6cd6401c2828f50d58c4cb7ca56aad1f26ad85a35cb4aab9a1220exe  
2025-08-14 08:51:31109b03ffc45231e5a4c8805a10926492890f7b568f8a93abe1fa495b4bd42975exe AnyDesk
2025-08-14 08:51:292a32f7e01f5e5b3873ad6976b5b87f9093a8ea8e72b7cdae695fdde85f6fc6c8rar  
2025-08-14 08:51:265bc957839c9488b18f8e394018461da2ba17718dc6f269d1391e845d4b1bace5exe 
2025-08-14 08:51:26bdad79dddd27fbf381f0e64b53bee42347fbfc356320749fb852e9ea67a826ffexe 
2025-08-14 08:51:2646f7b88ae8b06fbe1b1d4ca49d9b1af4811639ceb61096613eb1611186ea9361exe  
2025-08-14 08:51:2611bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5exe 
2025-08-14 08:51:25ded3e961c5c0bacd4f30f0c91844c1bf6405507d8f20653662de2a059242315ejson  
2025-08-14 08:51:232e89d5d6b99a6c49b4a2049756c2457b0ba74eecb7888de126c6659d8e78fb86bat  
2025-08-14 08:51:23974282380c85452918f2d2c241b4bceb6c567981956dd3a5bdab6717430e8ef5exe  
2025-08-14 08:51:2292cef683c8967ddc0372d1b8ad1266a95815ff4a0d0e77671d94f7ad96e4f1ccbat  
2025-08-14 08:51:21507c5045dcbfb3bf510bf4b35e63a21a65ae66da6d150e7ac645ccb8c2d1d80cexe 
2025-08-14 08:51:182538c9be4ed3126ddc13b5613661da583f0ac11c587704ca2c251b5e98f03d4cbat  
2025-08-14 08:51:1841ee8f78bc0b6d3421d4503998dabf125fae16c38c3a224047886e419bf544d0exe  
2025-08-14 08:51:18507c5045dcbfb3bf510bf4b35e63a21a65ae66da6d150e7ac645ccb8c2d1d80cexe 
2025-08-14 08:51:176f9d22b46c85dd1b555c71a7e5343057da63778378faffca5775ee34b1e9ae69txtAnyDesk
2025-08-14 08:51:17d38d06c432a351321ee4ec7913a185ebb61fc6aae8a7b892cb9f62cca9be2832exe 
2025-08-14 08:51:16b5e51df99195ca21b09997003b99410febe3073d08f6214a96dc00ac67a29114json  
2025-08-14 08:51:16eaa23102326532eee19e51194f00994cf5ad9aedd8e24ea0ef1b2172382badf8exe  
2025-08-14 08:51:16ce389d2cc91ef8d9ff8b063404658ed1386d0eabe19150e4d33ae21fb7f6f662bat  
2025-08-14 08:51:12ded3e961c5c0bacd4f30f0c91844c1bf6405507d8f20653662de2a059242315ejson  
2025-07-12 06:45:180bdadbc5f5d6cd6401c2828f50d58c4cb7ca56aad1f26ad85a35cb4aab9a1220exe  
2025-07-12 06:45:172992cfd555b4ecb722302e37b2de53c2f96fe0032a3d948afcf053dc247c55f7exe 
2025-07-12 06:45:1105e754d46b47c138c77595a4f71af97b8446d157cf6873aa2fab349a7b0c4aecexe 
2025-07-10 11:06:577bfca2a80aefdedb07ce74460dd47fee71c4a8dddb7902051a6c21e7e4f292f4exe  
2025-06-07 21:26:10abf1e20219fbb688ef92d246b6fea0649fa99fcde3b24f05174cbc02da6ce0abexe