URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 103.139.44.52
Firstseen:2022-11-29 07:28:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-29 07:28:40 103.139.44.52Not listedAS135905 VNPT-AS-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-10 09:23:08http://103.139.44.52/OneDrive/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-12-08 07:25:34http://103.139.44.52/outlook/csrss.exeOfflineexe Loki ext abuse_ch
2022-12-06 07:25:34http://103.139.44.52/msnserver/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-29 07:28:40http://103.139.44.52/office365/csrss.exeOfflineexe Loki ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-10 09:23:0880cc6c5ec49a97e5da1d8525ee12cdc2778b112bf3b0b3d84051105ef1af22f0exeLoki
2022-12-08 10:56:352f7a4529d1a003b5e32724dcc1177ad067e09120788dfaf18fa9759811561044exeLoki
2022-12-06 09:51:294f52928b3599dde5382b84b16cf8482a5e840f30f94ef11a100f624ac1839506exeLoki
2022-11-29 10:47:03062841c1e780acd00ef44b49f93e2c82189e1411e735c8da63782f8ae6159405exeLoki