URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.172.73.140
Firstseen:2022-03-15 14:40:03 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-15 14:40:06 107.172.73.140107-172-73-140-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-12 15:48:04http://107.172.73.140/700/vbc.exeOfflineLoki ext lokibot ext ps66uk
2022-04-12 15:09:04http://107.172.73.140/bbm/gmg.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-04-11 17:46:04http://107.172.73.140/gee/man.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-04-08 09:22:04http://107.172.73.140/mum/guy.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-04-06 15:34:04http://107.172.73.140/aba/gun.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-04-06 15:34:04http://107.172.73.140/imo/don.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-04-01 13:57:04http://107.172.73.140/tog/alu.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-03-31 08:59:04http://107.172.73.140/iri/waw.exeOfflineexe Formbook ext opendir abuse_ch
2022-03-22 18:24:05http://107.172.73.140/qmq/jkj.exeOfflineexe Formbook ext opendir abuse_ch
2022-03-22 18:24:05http://107.172.73.140/tot/dmd.exeOfflineexe Formbook ext opendir abuse_ch
2022-03-21 09:15:05http://107.172.73.140/hmh/bob.exeOfflineexe Formbook ext opendir abuse_ch
2022-03-15 14:40:06http://107.172.73.140/acc/man.exeOfflineexe Formbook ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-13 02:46:0423da9c9cb69beaa4ef047739cda8f315a396fcda1155272b1a2f4614c5e77bc0exeLoki
2022-07-12 15:48:043108a141b8199249069f2bbf1570a719a168d4460d4997aba1eadc4e06f060faexeLoki
2022-04-13 02:36:143000e985c0242ce67c2848597c21788af22c353da3a13a1f3cbc261d857504caexeAgentTesla
2022-04-12 20:30:35d55001b5ff0b9126c16a7fc8f20c72c56eb1a2a9d9f1e9867481c1f9f85feb2eexeAgentTesla
2022-04-12 15:09:04f9a3872603bab9d16727daf3e24705ff94100d4bf2838679b5e9288aa02bd32aexeAgentTesla
2022-04-11 17:46:04f66df3806ed429acb7329a8a10fa3f86dcbda02376e4714990cefd6564a94678exeAgentTesla
2022-04-08 09:22:046d8fe8e4b99da6d816d7335bd1ace36db4706fda0e1e46dceb5657ca1a57d81cexeAgentTesla
2022-04-06 15:34:047e840527c08cc44418a9d45ce4311b201cf5e15f85efb806ca81edd7d5c29fd8exeAgentTesla
2022-04-06 15:34:04fb37efb44fe9befa68076e623e3f2ba4d1f4f13c65892ce04227be3857b77f04exeAgentTesla
2022-04-01 13:57:047817d24ac9fa9ebe89664fd87eaf065f6e71a977bfe14154924c98a596ae6e74exeAgentTesla
2022-03-31 08:59:04345a777b503e381bf28a664c28a9945255c93a2ee597b3da5bea25b81e3d70b7exeFormbook
2022-03-23 10:18:191adbcbe596643451133f94a5976e52a5e8f608682124477f47141996eb5a98d7exe 
2022-03-22 18:24:05a859b5915c6f8b44328717583e36f7ae1020f1cbdd35e93e17e232370865e3ddexeFormbook
2022-03-22 18:24:04dd39f14948021a7f17de30d38f334142b9f7c26c2fffb174f689bccddce94b29exeFormbook
2022-03-21 09:15:05ca77df966e202e0eab6d3c2280f95fb59aee28b5e9e540be3dca1d66c46bf2afexeFormbook
2022-03-15 14:40:0519d34ef30d521849caa19f1cf2adc2f4c8097483cfb436ff6066ad60387b630fexeFormbook