URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 01:12:21 | 195.35.6.15 | Not listed | AS47583 AS-HOSTINGER | IN | yes | |
| 2020-03-03 08:22:05 | 2.57.88.116 | Not listed | AS47583 AS-HOSTINGER | NL | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-04-16 15:36:33 | http://umeed.app/ztig/uH.exe | Offline | remcos | |
| 2020-04-13 16:37:06 | http://umeed.app/zac/qs.exe | Offline | remcos | |
| 2020-04-06 20:59:34 | https://umeed.app/zt/Oo.exe | Offline | rat remcos | |
| 2020-03-05 11:30:34 | http://umeed.app/spp/gu.exe | Offline | exe RemcosRAT | |
| 2020-03-03 08:22:05 | http://umeed.app/zp/SP.exe | Offline | RemcosRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-04-16 15:37:36 | 4024ebda5d47c496c51c7fe116ea84a75c5388f568f1e9f45dbea9ce849b3df2 | exe | RemcosRAT | |
| 2020-04-13 16:37:06 | eed41a2c1215d2ca0ef2022172504a565b7a968e6263e173fceb6f1b1747d795 | exe | RemcosRAT | |
| 2020-04-06 20:59:34 | 30f27133ef88292cc6d00977059dd9a2ef5799a3e09c506854d10774bb9471a9 | exe | RemcosRAT | |
| 2020-03-05 12:32:13 | b166391f2c3d809e4c0a2fb2355395b2c695826e549b1f80c9775f0e5b8f6b2e | exe | RemcosRAT | |
| 2020-03-03 08:22:05 | 98820de764cbde6715e8315bcfe06db176d023078e9327703a38f3ee36820c11 | exe | RemcosRAT |
IN
NL