URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.173.219.122
Firstseen:2021-08-25 06:59:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-08-25 06:59:04 107.173.219.122107-173-219-122-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-09-22 06:00:04http://107.173.219.122/files/loader3.exeOfflineexe Loki ext opendir abuse_ch
2021-08-25 06:59:04http://107.173.219.122/files/loader2.exeOfflineFormbook ext Loki ext abuse_ch
2021-08-25 06:59:04http://107.173.219.122/files/loader1.exeOfflineFormbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-09-29 07:33:0781b5af95b241a5a77293e9a905ea32c69da468f568f798ec5ea535071e930596exeFormbook
2021-09-29 03:50:5164e3a0f2298f21833eb7a9c51aa0b2b8d3354bdcefb0156bb34371e3163d8b3dexeFormbook
2021-09-28 08:51:23cf3038247c7a2a5779f655fdf594bdad56b22d198b6edb1c3197b84d9c4f153aexeFormbook
2021-09-28 02:05:1431accabae2032a0fda8dd449182167521360e258df6ebd2316130399d910e990exeFormbook
2021-09-26 23:36:04c5ccdeea44050d8be9cf04b42ba6336dfd81e4a930ec6cd916f5f4e3a5f713bbexeFormbook
2021-09-26 22:47:37907b94712371352eba65c78fb8e4e99c68df75b2c0b9ce8a2a4ad91160df9f5eexeLoki
2021-09-24 08:44:093dfa10d42004768b9da7da94dc0586a0b9d68b56dd6bf5b5057b6b896eec5336exeFormbook
2021-09-23 22:25:275b3c0bd4b2b9eec9cc2bf6930eed386d51ff07746c9546af396e16eefc313758exeLoki
2021-09-23 22:21:056724b4abaf05bc011ee266d499d2eecadd61a305cd0a8e3c099193a3b9323a3cexeFormbook
2021-09-23 18:22:56e777ad1dca2df7e7c9b06832349f82e10af2259f68b0f855b10899fae8a29e7aexe  
2021-09-23 11:18:05fbcdadd58c74c8536b737c3fcd91f009562181986c1f9d1a455934a2bcd37bf0exe  
2021-09-23 02:14:53990a8fa7e96d2cd90b09ab39794df984bc153d0dcd390afbca19a42b689d4e7dexeFormbook
2021-09-22 06:00:04d8d1ebdb241277b39607ea8d4c63853c25b6523a3a88d720373a0f9efd03a686exeLoki
2021-09-21 14:41:3864c00be3d0bc5f000ee6d2d6d49e72c9e9f36090f19b7f9620ff0993a0e84025exeFormbook
2021-09-21 05:41:308a95ac711537aeb1c93c61e541077005f5226e4150c2669742d1b612cfc25788exeFormbook
2021-09-20 21:24:211771bccdd4c4fdc7d50d97ac10e5b1e0f980a4ff31233c59e9cfa17e9cd36a24exeFormbook
2021-09-20 12:40:45b32448dbeec13e1eb23e55a57ffc06f9dfc8fd44687e19fc0be1c4fbabc10abbexeFormbook
2021-09-19 22:19:368a88211f7dc2c10cdbdc9b2c024c7ab7584f4a87594861b0c701549e3129314dexeLoki
2021-09-16 23:58:3502dba9f39d37b0df394b43243dae2053bb472b55a4101c82a640912aaa01fd4aexeFormbook
2021-09-15 02:22:357fd87c43fb93fdecdab5de1a532b259a4193ef217658c43b0f2bcc0332d92cdfexe  
2021-09-14 18:35:291b0540e16c42a94f40853c6e728f5ab380a939a37e0eecf99027ae1cab745d78exe  
2021-08-31 10:59:18659e5f23a06a5a17740693c0fc0094fc98ba1f6ef03b2fac8d97cff377a69480exe 
2021-08-30 01:56:4426abff4dad54deb9aff14e22b6df1f6b61e6638e543f75f0b28e58740d72f0e5exe Loki
2021-08-26 15:02:51b6265825a201f66e512e8288a49c0112b0dcda84fde2904152b2f525edd32fd1exeFormbook
2021-08-26 08:27:192c9f9b7441e5626155e10dfdd98926a04653454723069560bebe6d07a7d1d405exeFormbook
2021-08-25 22:12:57c98a42f6e9e5f2e0e12f69c4ce7022265b7db271369ddb2ebff3348c0434d3cfexeLoki
2021-08-25 11:16:2871335267a0a48bbcf678e354b421445d3db926ec5dd9b40c2a004cebb9b166f0exeFormbook
2021-08-25 06:59:04a4bbac6b142c63da7c64937cc5beda93009b5be72481e98d514d62ee29801b12exeLoki
2021-08-25 06:59:04273f8137fbe63ffef8f64fa9efad27fac451ffec71edaf1a4a7769a277a2379fexeFormbook