URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.173.9.74
Firstseen:2025-07-28 14:30:05 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-28 14:30:17 107.173.9.74107-173-9-74-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-26 07:15:08http://107.173.9.74/cloverfielsdmanagerevenings...OfflineAgentTesla ext vbs abuse_ch
2025-08-26 07:15:07http://107.173.9.74/newestmanagerggsxxxscript.vbsOfflineAgentTesla ext vbs abuse_ch
2025-08-25 07:04:15http://107.173.9.74/newssxxxdriConvertedFile.txtOfflineAgentTesla ext ascii Encoded rev-base64-loader abuse_ch
2025-08-24 15:09:11http://107.173.9.74/forxlammetallickscript.vbsOfflineAgentTesla ext vbs abuse_ch
2025-08-23 09:34:19http://107.173.9.74/goodnewswithgreatnewsgivenn...OfflineAgentTesla ext hta abuse_ch
2025-08-21 06:28:09http://107.173.9.74/metallicka.vbsOfflineAgentTesla ext vbs abuse_ch
2025-07-28 14:30:17http://107.173.9.74/metallikkkkcccevening.jpgOfflineAgentTesla ext abuse_ch