URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: twart.myfirewall.org
Domain registrar:Ascio -
Domain registration date:2012-02-24 16:10:55 UTC
Spamhaus DBL :Malware domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-04-20 10:57:02 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :18

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-14 15:24:39 91.92.241.145SBL686267AS214943 RAILNET- NLyes
2025-04-28 12:42:33 107.150.0.72unassigned.quadranet.comSBL682038AS36352 AS-COLOCROSSING- USno
2025-04-28 06:55:26 213.219.150.114213.219.150.114.static.edpnet.netNot listedAS9031 EDPNET- BEno
2023-06-11 23:10:07 85.217.144.229Not listedAS16276 OVH- GBno
2023-04-28 04:02:37 185.246.220.173Not listedAS41745 FORTIS-AS- RUno
2022-04-20 11:38:14 2.56.57.193arekliniken.comNot listedAS3758 SINGNET- SGno
2022-02-10 17:09:27 212.193.30.119Not listedAS9123 TimeWeb-AS- RUno
2021-12-07 01:36:23 195.133.40.105Not listedAS210976 TWC-EU- CZno
2021-07-10 10:49:37 79.134.225.96Not listedAS6775 FINK-TELECOM-SERVICES- CHno
2021-06-25 02:17:30 37.0.11.124Not listedAS3758 SINGNET- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-05-30 10:59:33https://twart.myfirewall.org/bak_gmsbEd21.binOfflineAgentTesla ext exe GuLoader ext ITA reecdeep
2022-05-30 10:59:14http://twart.myfirewall.org/bak_gmsbEd21.binOfflineAgentTesla ext exe GuLoader ext ITA reecdeep
2021-06-25 14:59:33http://twart.myfirewall.org/conhosts.exeOfflineAgentTesla ext Cryptolaemus1
2021-04-20 10:57:07http://twart.myfirewall.org/taskmgrs.exeOfflineAgentTesla ext exe NanoCore ext rat Xpertrat abuse_ch
2021-04-20 10:57:06http://twart.myfirewall.org/firewall.exeOfflineAgentTesla ext exe rat RemcosRAT ext Xpertrat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-06-02 22:16:0790961bed36c6423c65277ac18047709609da46229727892e04a6dc8473bd7a14unknown  
2022-05-30 14:53:384bcdb175ec24a996919592d2aa0b79eb65adec30f9d6b09c42c6228a6c5aa668unknown  
2022-05-30 10:59:14667c7af2e6a02be910148f0f954b0473721ff0daa08ab89106999802cb34272funknown  
2021-04-26 01:13:21698d686ce288fb2943f7587b30d1dfa01f0ba1f5e3de8be766770ee98f945acfexeNanoCore
2021-04-26 00:20:29f8e52fa75724eb08c0ec68db6799740ad36c7178b8f0dd7c8b0ee755ff60c653exeXpertRAT
2021-04-25 23:59:00520457786da0e88af9df6022e8e87642d0cc6c3b1aaf34082b929a0b3aed6074exeRemcosRAT
2021-04-23 21:27:080b85c64339f4fb161e5fe4972ebf6832f06969f3f5f05dbfd636c75bf61ea432exeNanoCore
2021-04-22 05:55:11662da15ae88e1dfa28cc07591f1e5e964a9cfa1a75f5ac74b534de105c2402f1exe AgentTesla
2021-04-22 05:53:06877b28707372fb7365c52a314233c74877045cf1d8143fe83fb257f0bf90c248exeXpertRAT
2021-04-21 13:17:4789b7ce8de53ccf4aff814e942aa9042022e4644520a09ee1b0b13a429d552ea1exeAgentTesla
2021-04-21 13:13:037aa6ba1ed3e72514eac19d8b9ee4f95a17e33b63159bc75bd57ad8b38ce6361eexeXpertRAT
2021-04-21 00:59:57d5325b0dfdd73327d48c0e069567ce843a68f10d7fe0301a74dad13d6422eee2exeXpertRAT
2021-04-21 00:59:543f2ce17fe342c19e6ac9890f379841df3c448099e6565b9906538b463fc02932exeAgentTesla
2021-04-20 16:25:098a9a6384ca9858fd73b17063871825e60a989f230bf46bbe478c723e13f7cfadexeRemcosRAT
2021-04-20 16:22:278a5feb638a86eef3e912827fab799130ab284c72275c74bfd8449c10ab41ff2fexeNanoCore
2021-04-20 10:57:07fc8d2060f52b693d1745bac54a0943292519d643917590d4ded54a9cbd96ea7aexeNanoCore
2021-04-20 10:57:059626b19106a81d22416acbbe7ea291de316ca3a8f359beb9fe09850649fd5292exeRemcosRAT