URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 1.14.61.188
Firstseen:2021-06-15 03:32:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-06-15 03:32:06 1.14.61.188Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-09-13 08:56:04http://1.14.61.188/pay.exeOffline32 exe Gh0stRAT zbetcheckin
2021-06-15 03:32:06http://1.14.61.188/3306.exeOffline32 exe Zegost zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-06 15:47:189149bb7d47ca504505e3d7d136b57717109dac61354647b774ed0847fe7df7bbexe  
2021-09-13 08:56:04e046697b4102be8e3ad4b6e04524e7248d86b58f6d9f4884357fd33768878fbdexeGh0stRAT
2021-07-14 13:10:095178bfc480d21beef6d61a03f667447063c8d0a31e22c1117ce38a802415c56cexe  
2021-06-15 03:32:063c536c1558eba42c1967d9732bf9afd25c9c3c28bfbdc0028b945e88f1141d90exeZegost