URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: tgc8x.tk
Abuse complaint sent?: Yes (2022-11-02 06:10:02 UTC to abuse{at}freenom[dot]com)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-11-02 06:06:09 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-02 06:06:13 50.115.174.192mail.etheereum.orgNot listedAS32875 VIRPUS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-11-02 06:07:14https://tgc8x.tk/tt/BCBCBDHDHD.exeOfflineexe RemcosRAT ext jstrosch
2022-11-02 06:07:14https://tgc8x.tk/tt/eurob.exeOfflineexe RemcosRAT ext jstrosch
2022-11-02 06:07:13https://tgc8x.tk/t/RHDGHGDSYTUR.exeOfflineAsyncRAT ext exe jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/HENWAR.exeOfflineAveMariaRAT ext exe jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/johnrem.exeOfflineexe RemcosRAT ext jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/henrem.exeOfflineexe RemcosRAT ext jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/VCXVNCXMCXGJJGDF.exeOfflineAveMariaRAT ext exe jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/XCXCBBDFDHHD.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:13https://tgc8x.tk/tt/w.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:12https://tgc8x.tk/tt/marryoo.exeOfflineAgentTesla ext exe jstrosch
2022-11-02 06:07:12https://tgc8x.tk/tt/ptr.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/BCVCBBDHDDHD.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/hum.exeOfflineAgentTesla ext exe jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/lamboo.exeOfflineexe RedLineStealer ext jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/africa.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/kexe.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:07:11https://tgc8x.tk/tt/maryxloader.exeOfflineexe Formbook ext jstrosch
2022-11-02 06:06:13https://tgc8x.tk/CVBCVBVCBVCBD.exeOfflineAsyncRAT ext exe jstrosch
2022-11-02 06:06:13https://tgc8x.tk/t/CVBCVBVCBVCBD.exeOfflineAsyncRAT ext exe jstrosch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-11-04 10:01:336bcfe7bb68fe8ed455aa7b27eaf36bd89748f010201889626804c57f46c15cc0exeRemcosRAT
2022-11-03 11:21:5311a2113e2974db7c18160ff2993c1513f6fa22ef3e86102dd1df775ebd6ea9e0exeRemcosRAT
2022-11-03 06:52:22c2806b394c62e13d3cfc2675aab8447394f8ba0ea357f9bf2073cc811b8fecc1exe  
2022-11-03 06:48:114a9f8a3b847fa9d2e854d3a7235ddee8e4c093d04c3901f006d430be1060fae5exeRedLineStealer
2022-11-03 03:58:336d3397c687aea5017b90a5e96adc6fbfb0429d56a8b2ead1f1d4273994952379exeFormbook
2022-11-02 07:57:15ec28d0562a15c6057e0d7b599687071f43807aa54fb8fad60138da24fb224afaexeRedLineStealer
2022-11-02 07:45:0765054687e67c867b4f3a1fe66888dbc1e43f1152d44ba8a82e98f4374d54ec1dexeRemcosRAT
2022-11-02 06:07:14238e7b87bd6d152fce3ae3dbe8ea4a9f3b56c883944cb93695c58fdc20aad6e8exeRemcosRAT
2022-11-02 06:07:14dd228418c8681d5655b1189c61249f20c9da5e1661cad7efacea62a03fcf1687exeRemcosRAT
2022-11-02 06:07:13248d6e28ce68880892021793e9a21f85a5a9ae64f25ed12af5ddba413084adb9exeAsyncRAT
2022-11-02 06:07:139b47c2a93d98536ae14add21abe194fa42611cd51a6d7c34980dc31f83f6f53eexeAveMariaRAT
2022-11-02 06:07:137458ae3948da0ce72c63f099f0c15240361d61805b6c4aafd6aee84de3c4132fexeRemcosRAT
2022-11-02 06:07:13dfca7ce647ee8994cba9317516ce7f58b2b175f815fd5336dbfed34ccad5c4deexeRemcosRAT
2022-11-02 06:07:1342ff33d8a2c198145c876fbfab4855fa43faaf292d10c73f144619c34714f97eexeFormbook
2022-11-02 06:07:1397601111954fcaf73abb4283200237edd6e08c37533a28f66a50aa0808484dddexeFormbook
2022-11-02 06:07:131acb33d44ff0dd6c5574b9546e688cc401a390510c7d3d05b74b47f8118272abexeAveMariaRAT
2022-11-02 06:07:12c1bc25f768e41a646f902de9572b855ac973cfa7a9c6bef82c5a99123a72e67bexeAgentTesla
2022-11-02 06:07:12e1311c2daa9fd1d5a33362492509aa872040fa4a3539870229973616d65684b7exeFormbook
2022-11-02 06:07:11d4b16018f7ea64cf88506858f2ffab461a39bd1ecef83be0fc9a96266e4f6149exeFormbook
2022-11-02 06:07:1122e699dddb4e02a8f046243850a37c0f03295b5d2f95ed8f470919d916b30e51exeAgentTesla
2022-11-02 06:07:115e37a85642397700f4d2b763aef9debbed637b8d0a55caecd88b5deea01430fbexeRedLineStealer
2022-11-02 06:07:113c9ea84465ac087d0dda3ab93ad200e9913d527986ca8358d551ad81a14c9bfbexeFormbook
2022-11-02 06:07:118d2245952066731545e35c0dd194b48df2e16010d34136ed5b07bc96d763f613exeFormbook
2022-11-02 06:07:10a2942f4b52d24096733c6a8373bc3cee7f1823120bf652c688b8296b04a94a96exeFormbook
2022-11-02 06:06:137ff14c21fd0b01bdde72c128356802e29242809bd3965e234ac1231da1c0893aexeAsyncRAT
2022-11-02 06:06:127ff14c21fd0b01bdde72c128356802e29242809bd3965e234ac1231da1c0893aexeAsyncRAT