URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 104.168.46.107
Firstseen:2022-10-17 12:00:04 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-17 12:00:05 104.168.46.107104-168-46-107-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-24 06:02:09http://104.168.46.107/220/vbc.exeOfflineAgentTesla ext exe opendir abuse_ch
2023-03-24 06:00:11http://104.168.46.107/430/vbc.exeOfflineexe zgRAT abuse_ch
2023-03-24 03:00:09http://104.168.46.107/30..................30......OfflineRTF zgRAT zbetcheckin
2023-03-24 03:00:09http://104.168.46.107/20..........................OfflineAgentTesla ext RTF zbetcheckin
2023-03-22 19:19:03http://104.168.46.107/19..........................Offlinedoc SnakeKeylogger ext abuse_ch
2023-03-22 17:05:07http://104.168.46.107/219/vbc.exeOfflineSnakeKeylogger ext Anonymous
2022-10-31 13:02:04http://104.168.46.107/zxxsaassswq_zzaxxsccvb_zx...OfflineAgentTesla ext doc opendir abuse_ch
2022-10-25 10:57:05http://104.168.46.107/120/vbc.exeOfflineexe Formbook ext abuse_ch
2022-10-20 07:21:05http://104.168.46.107/127/vbc.exeOfflineAgentTesla ext exe opendir SnakeKeylogger ext abuse_ch
2022-10-20 07:20:05http://104.168.46.107/zzwqqwwsddsfsdferdfgdfgeg...Offlinedoc opendir SnakeKeylogger ext abuse_ch
2022-10-20 07:20:05http://104.168.46.107/zzwqqwwsddsfsdferdfgdfgeg...Offlinedoc opendir abuse_ch
2022-10-19 07:17:04http://104.168.46.107/78/vbc.exeOffline32 AgentTesla ext exe SnakeKeylogger ext zbetcheckin
2022-10-19 03:32:06http://104.168.46.107/79/vbc.exeOffline32 AgentTesla ext exe SnakeKeylogger ext zbetcheckin
2022-10-17 15:19:04http://104.168.46.107/@uuUASDbjasd@uhuasduyuASH...Offlinedoc abuse_ch
2022-10-17 15:18:05http://104.168.46.107/55/vbc.exeOfflineAgentTesla ext exe Formbook ext abuse_ch
2022-10-17 12:00:05http://104.168.46.107/50/vbc.exeOfflineAgentTesla ext exe SnakeKeylogger ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-24 06:02:09d8c4477971a15461d08f74725d2922f5e2400d857f539648a3b4f9ea940a8ab8exeAgentTesla
2023-03-24 06:00:11e4ea5b2871c32f3d25689785ff260ae5e75e7117ed478dc2f9e8edd1c01030f4exezgRAT
2023-03-24 03:00:09becc292fb633a6d01d47ebf5cedcd0ca4ebe4ec3f7ec8feb64f244c6b3915a7artfAgentTesla
2023-03-24 03:00:09af6f64bdcb8dd561cda554933b57cf7d479c8079baf6a716be19ab03d359cbdbrtfzgRAT
2023-03-22 19:19:03cdf4664c93b698fdc7ccff8589a27bbd4b1ab01b33c44fa6a1ad63747be7e108rtfSnakeKeylogger
2023-03-22 17:05:07bdf329c1001b540fffb7ad110b6cf460a89c3408fbd62b15e7c55d8cdb55380eexeSnakeKeylogger
2022-10-31 13:02:04a46c348c9d64286aefd26a23100ecde7020886409cfa9fdb79a3c8b380d7574bunknown  
2022-10-31 08:43:50fb55a5d93e0d9aab4332e5ba708ba2c41095bdf854d25d7d688a29afbb822a3aexeSnakeKeylogger
2022-10-31 08:22:031142c04f790d684080f3b80c61dce80a1250038e681a4546559c272fc93708c5exeAgentTesla
2022-10-31 04:48:59ee9d1419958241265b597e044640a86739bd91e9a426bdd5dee1bf0b57355276exe SnakeKeylogger
2022-10-31 01:56:36068aaf69425a85656bb2c95d42360154f712851a273607cc4edc89242083c307exeAgentTesla
2022-10-30 23:04:47f2d2638afb528c7476c9ee8e83ddb20e686b0b05f53f2f966fd9eb962427f8aaexe 
2022-10-25 16:22:3151fed50e49897901d18109ff666e3ff6becaf4442d7b4f85a352513cdded551bexeFormbook
2022-10-25 10:57:05cea0844bf755c190793ac29a2cd95220862993a84c5924faeddce381fcdf063cexeFormbook
2022-10-25 06:23:57ab6ca79d5ad4fe400e7c57b831c71c0a11503f827e66abf52f51ba218854d7f9exeFormbook
2022-10-20 07:21:0579ce7bf9135fe898db020a36c73c12f10f39fe3546f8d688dd3d639bf3cb8f18exeAgentTesla
2022-10-20 07:20:05cbdbe327dc4e244532f83a27bbb4221d583bc2775db0479acfc3e726ce997803unknown  
2022-10-19 10:43:23fb766c403cf24a9d538597f9858130b3128cf4367018227bf5f58c06d1e8fdf5exe  
2022-10-19 07:17:04cb7655f9fc9a249fdb1cd7bb990efb0bd4fe1803f741869da6623bdf435964c7exeSnakeKeylogger
2022-10-19 03:32:068f3caefce2530518144bab9f75c4489f84b0fdacbebdc953ac41a73c95356f44exeAgentTesla
2022-10-18 01:26:2438bcc28d84c5523fe8e64b983a069c11e9109acb6e0eb290ca95139cddadae70exeSnakeKeylogger
2022-10-17 15:19:04ca2cb0e3a425a94c97aee05b1c28373010cc18b57968d1117d9474a97d5e6fc8unknown  
2022-10-17 15:18:058ccea9d264f5584180de3b726b676590bfec351367d48a03decb1ee37f9f3965exeAgentTesla
2022-10-17 13:15:3335a8230207c089a54d80a6b45299b23f67047eed4cb285dfb57834eb5a2be571exeAgentTesla
2022-10-17 12:57:53850e278ca4d31e19fb49340aa795a0803220b811119488eb1edc082f11f5e8d2exeAgentTesla