URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.174.224.202
Firstseen:2021-08-18 17:49:02 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-08-18 17:49:06 107.174.224.202107-174-224-202-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-08-19 13:03:06http://107.174.224.202/saint.xlsxOfflineLoader NanoCore ext Cryptolaemus1
2021-08-19 12:50:06http://107.174.224.202/saint.exeOfflineNanoCore ext Cryptolaemus1
2021-08-18 19:43:06http://107.174.224.202/fish.exeOffline32 exe NanoCore ext zbetcheckin
2021-08-18 17:50:06http://107.174.224.202/newme/saint.exeOfflineexe NanoCore ext opendir abuse_ch
2021-08-18 17:49:06http://107.174.224.202/newme/nass.exeOfflineexe NanoCore ext opendir rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-31 14:18:0348b183c97788bcb734dfef7c34c8e85c68be28730ebc19ab3a66ac6294412c02exeNanoCore
2021-08-25 06:15:52deb3aee37e495b0f30c806fd13b6380fd18f4edfea04ae394742a0140e302d73doc  
2021-08-25 04:59:46b616bf69d390a44e05e1fb7c1cc764fc2c397237f813b9911cd2de1e4feb4129exe 
2021-08-25 03:50:41c39172c2d31ff7507d5735c70d244c0c44e49725bf9400cbea19553048e8e00ddoc  
2021-08-19 13:03:06024edeef724eb2dd893ce005ff62bd7de24535ff75e92d0af813d3a998df8914unknownNanoCore
2021-08-19 12:50:06801761f7af7bd86d136b36b7f4b48550e9258cfec68b482210da6561b8e61f68exeNanoCore
2021-08-19 11:43:33801761f7af7bd86d136b36b7f4b48550e9258cfec68b482210da6561b8e61f68exeNanoCore
2021-08-19 11:42:56801761f7af7bd86d136b36b7f4b48550e9258cfec68b482210da6561b8e61f68exeNanoCore
2021-08-19 07:13:50b0da85f7160cacf3021a59bb14ca11e2c0df85750ad60374bde8767b8fba763cexeNanoCore
2021-08-19 07:07:46b0da85f7160cacf3021a59bb14ca11e2c0df85750ad60374bde8767b8fba763cexeNanoCore
2021-08-19 03:31:58b92b9d4ae9523e48b97add5bfd7d5406a0dd35be2d09211eadebe32ac4bb82cdexeNanoCore
2021-08-19 03:25:03b92b9d4ae9523e48b97add5bfd7d5406a0dd35be2d09211eadebe32ac4bb82cdexeNanoCore
2021-08-18 19:43:0695180da7cbc5ead1e82d68aa9e529390cf5f2b7e9b647dbc4bee8c42952e27b9exeNanoCore
2021-08-18 17:50:0695180da7cbc5ead1e82d68aa9e529390cf5f2b7e9b647dbc4bee8c42952e27b9exeNanoCore
2021-08-18 17:49:0595180da7cbc5ead1e82d68aa9e529390cf5f2b7e9b647dbc4bee8c42952e27b9exeNanoCore