URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-08-22 16:53:09 | 65.21.85.206 | static.206.85.21.65.clients.your-server.de | Not listed | AS24940 HETZNER-AS | FI | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-08-22 16:53:16 | http://ustaxes.net/bincnew1.hta | Offline | AveMariaRAT | |
| 2025-08-22 16:53:13 | http://ustaxes.net/fire32.pp | Offline | RemcosRAT | |
| 2025-08-22 16:53:10 | http://ustaxes.net/fire2.xx | Offline | ua-wget | |
| 2025-08-22 16:53:09 | http://ustaxes.net/bincnew32.hta | Offline | RemcosRAT | |
| 2025-08-22 16:53:09 | http://ustaxes.net/360055.hta | Offline | RemcosRAT | |
| 2025-08-22 16:53:09 | http://ustaxes.net/syswsl.xsx | Offline | RemcosRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-08-22 16:53:16 | b64dbd49ac4a47a4bad1a56e586edbdb222dead69226e97c94cbb7d2152b63df | hta | AveMariaRAT | |
| 2025-08-22 16:53:13 | ca7a1bd1d8a5514ec743b1a43663a2a4eacefb4aea8c31ef6cfc682c3f3a69df | exe | RemcosRAT | |
| 2025-08-22 16:53:09 | 1cfe161149571e556183b6db50bf76b0deb6e0bd377e81b1a007dd884dbf0b7d | txt | ||
| 2025-08-22 16:53:08 | c83d5bef9e2ab51c579431aecf23ebb4dc71eea9d475d46da89b70dcf4b669a6 | hta | RemcosRAT | |
| 2025-08-22 16:53:08 | 17179c73942c7bd427ea534efb1452991c037616294402e1ae231627f55eca21 | hta | RemcosRAT | |
| 2025-08-22 16:53:08 | c31a537a688da3310d621d985af0857ec1e3f6bfc0ef39075cb3c8b93f5970dc | exe | RemcosRAT |

FI