URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.172.81.7
Firstseen:2023-03-03 14:11:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-03 14:11:11 107.172.81.7107-172-81-7-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-06 10:18:06http://107.172.81.7/1522/vbc.exeOfflineexe Loki ext opendir abuse_ch
2023-03-04 05:50:06http://107.172.81.7/cc............................OfflineRTF zbetcheckin
2023-03-03 15:33:05http://107.172.81.7/2030/vbc.exeOfflineexe Loki ext opendir abuse_ch
2023-03-03 14:11:11http://107.172.81.7/2031/vbc.exeOfflineLoki ext lokibot ext James_inthe_box

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-06 10:18:05213733de61216a784d1133b8fcfcf7fdb5df435edad425bb3476b250a86e18f8exeLoki
2023-03-04 05:50:0646e413bc266891295b80f03d7fc987bde2d18f979a0709942d7d799ef787ba9brtf 
2023-03-03 17:42:448b5d2f25a3b2c3ca76ff1815a0a45442bd4e1e8b74709af37670208f397f4ad5exeLoki
2023-03-03 15:33:0599e2a2ff576947884f1b3019b01893b5e1df07e20187c9de9f274bbb971118dbexeLoki
2023-03-03 14:11:05ef683b83b977511f40064d0b2b35c9147c5eb3b0b54fa538be2147fef93b3089exeLoki