URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 1.94.97.137
Firstseen:2023-11-26 14:57:03 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-26 14:57:07 1.94.97.137ecs-1-94-97-137.compute.hwclouds-dns.comNot listedAS55990 HWCSNET- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-01-13 06:06:54http://1.94.97.137:8000/cobalt_strike_4.7_www.d...OfflineCobaltStrike ext jar adm1n_usa32
2024-01-13 05:59:30http://1.94.97.137:8000/PSTools/psfile.exeOffline adm1n_usa32
2024-01-13 05:58:14http://1.94.97.137:8000/cobalt_strike_4.7_www.d...OfflineCobaltStrike ext jar adm1n_usa32
2024-01-13 05:54:43http://1.94.97.137:8000/PSTools/pssuspend.exeOffline adm1n_usa32
2024-01-13 05:54:34http://1.94.97.137:8000/PSTools/psping.exeOffline adm1n_usa32
2024-01-13 05:54:31http://1.94.97.137:8000/PSTools/pslist.exeOffline adm1n_usa32
2024-01-13 05:54:24http://1.94.97.137:8000/PSTools/psloglist.exeOffline adm1n_usa32
2024-01-13 05:54:12http://1.94.97.137:8000/PSTools/pskill.exeOffline adm1n_usa32
2024-01-13 05:53:50http://1.94.97.137:8000/PSTools/PsExec.exeOfflineexe adm1n_usa32
2024-01-13 05:53:48http://1.94.97.137:8000/PSTools/psshutdown.exeOffline adm1n_usa32
2024-01-13 05:53:39http://1.94.97.137:8000/PSTools/pspasswd.exeOffline adm1n_usa32
2024-01-13 05:53:35http://1.94.97.137:8000/PSTools/PsInfo.exeOffline adm1n_usa32
2024-01-13 05:53:12http://1.94.97.137:8000/PSTools/PsService.exeOffline adm1n_usa32
2024-01-13 05:53:09http://1.94.97.137:8000/PSTools/PsGetsid.exeOffline adm1n_usa32
2024-01-13 05:53:09http://1.94.97.137:8000/PSTools/PsLoggedon.exeOffline adm1n_usa32
2023-11-26 14:58:23http://1.94.97.137:8000/PsExec.exeOffline abus3reports
2023-11-26 14:58:12http://1.94.97.137:8000/64_6666.exeOfflinemeterpreter abus3reports
2023-11-26 14:57:07http://1.94.97.137:8000/axx.exeOfflineCobaltStrike ext abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-25 07:11:450c902ce2df6616f859337d5262bad20feda402aa2fff6d650c308ceea7c0f765zip  
2024-01-25 07:11:44e6ba4e961e5d0e08fac98676bf42ebe0823d5b83efaa977247d7f4db107a5bb5exe  
2024-01-25 07:11:43796e27d2c1740fe728d3daf7c63e1689278e0dfabcfbea8b2cc99516e5cbb195exe  
2024-01-25 07:11:39513f84e1174150fb623d21d3489233eba6665e9f074e1a85033ffa23a0cb3913zip  
2024-01-25 03:23:38765adb5b853a950fc70c2596a4c2bd89a07eb715882a86906201e83b6fbe05bbzip  
2024-01-24 12:12:43c6242d44adb8e2d05857bfc6fbcf7991d11cc64528e67a43a7146841b7b609cdexe  
2024-01-24 11:26:1538225c944054a0c174e1cbba405fa2fb607ff7a78ca3095e54d5ce8fa522c5c5exe  
2024-01-24 06:19:34a55dc36e03b16c79b9037f89ddac4318bf9b2fc113f5b1fb3fa72f3e6f572044zip  
2024-01-23 14:29:121bdd5e709ff102341e43a928b3d57796bc0fc9c395b9dc7540911b664ea8d7bazip  
2024-01-23 10:05:474ea3dd52523ec8de26268f3381f4bdf3c433486e4e8de103c4b42b9c753ee773zip  
2024-01-23 10:01:26ab65a18783b00c3b2627c45365706197a4ad25a70a65739665350f0bb3f7932fzip  
2024-01-21 01:00:33d152c72cb4a157e4c47c21614faba9f97c95a07168a408d22a7bf7c968598467zip  
2024-01-20 22:01:27849df22891b3cf3d2ec4b4aa3efd8a955b764e2e87da3999ba58fad90dfc3b8dexe  
2024-01-20 17:03:3755f1de888ab45b3169b1000c1673e3c61b25c0c08e343b7b302b067efc08e098exe  
2024-01-14 04:11:23d01571dfc95d39ebc3befdf691d2ce2183c84b82fc7d46904efe63c41222fc0fzipCobaltStrike
2024-01-13 08:35:527794fe069e5166fc40b877f6fbe5b675d6ded7290fc4961058cfffa01b8e0008zip  
2024-01-13 07:08:067bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:59:307bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:54:437bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:54:347bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:54:317bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:54:247bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:54:127bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:507bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:487bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:357bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:127bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:097bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2024-01-13 05:53:097bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2023-11-26 14:58:237bf634e0d7a0b311e08ad0d0d453628f4fd559bcdd4bf9f05744571bc0e0f885exe  
2023-11-26 14:58:1091429407c3dcd1947735028b7b8632187edd45bbd0e19b7ae64a9a86574c3186exeMeterpreter
2023-11-26 14:57:06a38d5972dfa2fda1c5416ac91034c36462586575097d8b46775b2e689e5d9496exe CobaltStrike