URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sup3rc10ud.ga
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-08 03:13:09 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-16 19:57:25 104.237.252.54Not listedAS16628 DEDICATED-FIBER-COMMUNICATIONS- USno
2020-05-11 21:55:16 87.236.213.195195.213.236.87.mail.iranianwebman.irNot listedAS60178 IranianWebman-Network-Technology-LTD- IRno
2020-04-08 03:13:11 104.237.252.50Not listedAS16628 DEDICATED-FIBER-COMMUNICATIONS- USno
2020-04-25 15:08:21 88.218.16.18Not listedAS213953 MizbanDadehPardis- IRno
2020-04-21 10:10:39 5.56.133.1745-56-133-174.static.karizanta.comNot listedAS215419 karizanta- NLno
2020-04-08 03:13:11 88.218.16.218Not listedAS213953 MizbanDadehPardis- IRno
2020-04-20 06:51:31 213.108.241.185Not listedAS200296 HostandServerprovider- IRno
2020-04-20 06:51:32 89.33.246.124Not listedAS9009 M247- ROno
2020-04-08 03:13:11 213.108.241.164Not listedAS200296 HostandServerprovider- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-08 03:13:15http://sup3rc10ud.ga/Update.exeOfflineRemcosRAT ext JayTHL
2020-04-08 03:13:11http://sup3rc10ud.ga/Readme.exeOfflineRemcosRAT ext JayTHL

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-08 03:13:15395c9b5c9c1d4703f47afa1f50a8892edd1f4588f6a74cf141c81044064d26c7exeRemcosRAT
2020-04-08 03:13:114a679d8d9947349dc81cd1ee7495f1a64d064542fe7ab363eeea565aed8da83fexe RemcosRAT