URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 109.206.240.194
Firstseen:2023-02-26 09:42:30 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-15 13:42:09 109.206.240.194Not listedAS214238 iwihost- BGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-02-15 13:45:07http://109.206.240.194/cxz/XeoQYCxQMnyzL142.lpkOfflineopendir abuse_ch
2023-02-15 13:45:07http://109.206.240.194/cxz/lbvKElnksydrw205.asdOfflineopendir abuse_ch
2023-02-15 13:45:07http://109.206.240.194/cxz/YfyBGAD197.aafOfflineopendir abuse_ch
2023-02-15 13:45:07http://109.206.240.194/cxz/NEW_ORDER.exeOfflineexe GuLoader ext opendir abuse_ch
2023-02-15 13:45:07http://109.206.240.194/cxz/Rektificeres.exeOfflineexe Formbook ext opendir abuse_ch
2023-02-15 13:42:09http://109.206.240.194/cxz/DHL.exeOfflineFormbook ext abuse_ch
2023-02-15 13:42:09http://109.206.240.194/cxz/UErnUZhdfN126.ocxOffline abuse_ch
2023-02-15 13:42:09http://109.206.240.194/o/vooi.exeOfflineexe Formbook ext opendir abuse_ch