URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 104.168.7.197
Firstseen:2025-10-01 07:18:03 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-01 07:18:04 104.168.7.197104-168-7-197-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-03 05:32:11https://104.168.7.197/img/optimized_MSI.pngOffline JAMESWT_WT
2025-10-01 15:04:08http://104.168.7.197/155/IMG__pict0900000400003...Offlinehta abuse_ch
2025-10-01 15:02:07http://104.168.7.197/122/IMG___090000e098848774...Offlinehta PureLogsStealer abuse_ch
2025-10-01 14:59:07http://104.168.7.197/157/IM__Pic009405960060400...Offlinehta abuse_ch
2025-10-01 09:53:40http://104.168.7.197/img/optimized_MSI.pngOffline JAMESWT_WT
2025-10-01 07:18:04http://104.168.7.197/122/IMG___090000e098848774...Offlinehta abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-03 05:32:114378fae350b62cb5d4a1151b573aa39ed7e80efde38a0209f23fbd64cfc678faunknown  
2025-10-01 15:04:08e6a1a84f1bd7f19bed8364946512f3f39a0958cf5d236a236f216ffc7b9573f5htmlKatzStealer
2025-10-01 15:02:07837dac696a5a6d39add23990b6ec150c4ee86a770efa8c2d4d7a84e4d9c982d2htmlPureLogsStealer
2025-10-01 14:59:071422b3c6b965dea18640b5fe1df29540046204e09a8f672e6d7d115719e157a9htmlKatzStealer
2025-10-01 09:53:404378fae350b62cb5d4a1151b573aa39ed7e80efde38a0209f23fbd64cfc678faunknown