URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: water.s3.cubbit.eu
Domain registrar:Gandi -
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-04-13 13:38:27 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :19

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-21 18:17:45 151.115.166.114114-166-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:45 151.115.164.214214-164-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:44 151.115.164.223223-164-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:45 151.115.165.8888-165-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:45 151.115.165.8282-165-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:44 151.115.164.189189-164-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:45 151.115.166.144144-166-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:45 151.115.166.111111-166-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:44 151.115.165.8787-165-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes
2026-04-21 18:17:44 151.115.165.156156-165-115-151.instance.scw.euNot listedAS12876 AS12876- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-13 13:38:41https://water.s3.cubbit.eu/bmiSkak.txtOfflineAgentTesla ext ascii Encoded abuse_ch
2026-04-13 13:38:30https://water.s3.cubbit.eu/ccAoheF.txtOfflineascii Encoded rat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-13 13:38:4082475c6a3c2717b8b425ae29586ec1f599ab2267e056fb1f766d6e2b2f14e6d3txt  
2026-04-13 13:38:290ba97480238aa6495842685f0791ccfa68f98703660038d0f32acf9f303c4c3ftxt