URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 109.230.231.37
Firstseen:2025-12-06 17:34:06 UTC
Total malware sites :78
Online malware sites :0 (0%)
Offline Malware sites :78 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-06 17:34:10 109.230.231.37Not listedAS197071 ACTIVE-SERVERS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-07 05:32:06http://109.230.231.37:9999/beacon.pyOfflineopendir Riordz
2025-12-06 17:35:31http://109.230.231.37:9999/agent_dotnet_v2.exeOfflineopendir juroots
2025-12-06 17:35:31http://109.230.231.37:9999/multi_readme_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:31http://109.230.231.37:9999/agent_dotnet_v3.exeOfflineopendir juroots
2025-12-06 17:35:31http://109.230.231.37:9999/agent_dotnet_slim.exeOfflineopendir juroots
2025-12-06 17:35:26http://109.230.231.37:9999/panel_build_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:24http://109.230.231.37:9999/enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:23http://109.230.231.37:9999/enc_gui.exeOfflineopendir juroots
2025-12-06 17:35:10http://109.230.231.37:9999/test_gui_enc_v2.exeOfflineopendir juroots
2025-12-06 17:35:08http://109.230.231.37:9999/enc_c2.exeOfflineopendir juroots
2025-12-06 17:35:06http://109.230.231.37:9999/panel_dec.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:05http://109.230.231.37:9999/dec_v2.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:05http://109.230.231.37:9999/agent_dotnet.exeOfflineopendir juroots
2025-12-06 17:35:04http://109.230.231.37:9999/test_decryptor.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:04http://109.230.231.37:9999/dec.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:03http://109.230.231.37:9999/full_test_enc.exeOfflineopendir juroots
2025-12-06 17:35:03http://109.230.231.37:9999/dec_pc3.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:02http://109.230.231.37:9999/minimal_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:02http://109.230.231.37:9999/dec_fast.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:00http://109.230.231.37:9999/enc_pervictim.exeOfflineopendir rustystealer juroots
2025-12-06 17:35:00http://109.230.231.37:9999/test_gui_enc.exeOfflineopendir juroots
2025-12-06 17:35:00http://109.230.231.37:9999/uac_test.exeOfflineopendir juroots
2025-12-06 17:34:57http://109.230.231.37:9999/chromelevator.exeOfflineopendir juroots
2025-12-06 17:34:55http://109.230.231.37:9999/steal_browser.exeOfflineopendir juroots
2025-12-06 17:34:52http://109.230.231.37:9999/new_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:52http://109.230.231.37:9999/agent_mem_x64.exeOfflineopendir juroots
2025-12-06 17:34:52http://109.230.231.37:9999/dec_orig.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:51http://109.230.231.37:9999/agent_fw.dllOfflineopendir juroots
2025-12-06 17:34:51http://109.230.231.37:9999/chisel.exeOfflineopendir juroots
2025-12-06 17:34:51http://109.230.231.37:9999/lpe.exeOfflineopendir juroots
2025-12-06 17:34:50http://109.230.231.37:9999/new_panel_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:46http://109.230.231.37:9999/killer_crowdstrike.dllOfflineopendir juroots
2025-12-06 17:34:45http://109.230.231.37:9999/dec_unique.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:45http://109.230.231.37:9999/dec_victim.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:45http://109.230.231.37:9999/FleetAgentAdvanced.exeOfflineopendir juroots
2025-12-06 17:34:44http://109.230.231.37:9999/killer.dllOfflineopendir juroots
2025-12-06 17:34:43http://109.230.231.37:9999/FleetAgentAdvanced_e...Offlineopendir juroots
2025-12-06 17:34:40http://109.230.231.37:9999/svchost.exeOfflineopendir juroots
2025-12-06 17:34:37http://109.230.231.37:9999/FleetAgentFUD.exeOfflineopendir juroots
2025-12-06 17:34:37http://109.230.231.37:9999/agent_xworm.exeOfflineopendir juroots
2025-12-06 17:34:37http://109.230.231.37:9999/dec_unique_v2.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:36http://109.230.231.37:9999/agent_xworm_v2.exeOfflineopendir juroots
2025-12-06 17:34:34http://109.230.231.37:9999/test_killer.dllOfflineopendir juroots
2025-12-06 17:34:34http://109.230.231.37:9999/enc_v2.exeOfflineopendir juroots
2025-12-06 17:34:33http://109.230.231.37:9999/FleetAgentEDR.exeOfflineopendir juroots
2025-12-06 17:34:32http://109.230.231.37:9999/uac_bypass_multi.ps1Offlineopendir juroots
2025-12-06 17:34:31http://109.230.231.37:9999/agent_fw_x64.exeOfflineopendir juroots
2025-12-06 17:34:30http://109.230.231.37:9999/enc_orig.exeOfflineopendir juroots
2025-12-06 17:34:30http://109.230.231.37:9999/enc_pervictim_panel.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:29http://109.230.231.37:9999/test_pervictim.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:29http://109.230.231.37:9999/fixed_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:29http://109.230.231.37:9999/panel_test_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:29http://109.230.231.37:9999/com_uac_bypass.ps1Offlineopendir juroots
2025-12-06 17:34:28http://109.230.231.37:9999/safe_dec.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:27http://109.230.231.37:9999/agent.exeOfflineopendir juroots
2025-12-06 17:34:27http://109.230.231.37:9999/updated_enc.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:27http://109.230.231.37:9999/dec_fixed.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:26http://109.230.231.37:9999/safe_enc.exeOfflineopendir juroots
2025-12-06 17:34:26http://109.230.231.37:9999/nethost.dllOfflineopendir juroots
2025-12-06 17:34:26http://109.230.231.37:9999/test_enc_fixed.exeOfflineopendir rustystealer juroots
2025-12-06 17:34:25http://109.230.231.37:9999/enc_fast.exeOfflineopendir juroots
2025-12-06 17:34:24http://109.230.231.37:9999/nethost_aggressive.dllOfflineopendir juroots
2025-12-06 17:34:24http://109.230.231.37:9999/nethost_uac.dllOfflineopendir juroots
2025-12-06 17:34:23http://109.230.231.37:9999/agent_anycpu.exeOfflineopendir juroots
2025-12-06 17:34:23http://109.230.231.37:9999/mimikatz.exeOfflinemimikatz opendir juroots
2025-12-06 17:34:22http://109.230.231.37:9999/sideloading_agent.zipOfflineopendir juroots
2025-12-06 17:34:22http://109.230.231.37:9999/killer_eset_mbam.dllOfflineopendir juroots
2025-12-06 17:34:22http://109.230.231.37:9999/FleetAgent_MemoryOnl...Offlineopendir juroots
2025-12-06 17:34:22http://109.230.231.37:9999/rootkit.dllOfflineopendir juroots
2025-12-06 17:34:18http://109.230.231.37:9999/dkom.dllOfflineopendir juroots
2025-12-06 17:34:17http://109.230.231.37:9999/BdApiUtil64.sysOfflineopendir juroots
2025-12-06 17:34:17http://109.230.231.37:9999/test_nopass.exeOfflineBlackMatter opendir juroots
2025-12-06 17:34:17http://109.230.231.37:9999/agent_fw_x64.dllOfflineopendir juroots
2025-12-06 17:34:16http://109.230.231.37:9999/nethost_v2.dllOfflineopendir juroots
2025-12-06 17:34:15http://109.230.231.37:9999/FleetAgentFull.exeOfflineopendir juroots
2025-12-06 17:34:15http://109.230.231.37:9999/test_pass.exeOfflinelockbit opendir juroots
2025-12-06 17:34:13http://109.230.231.37:9999/agent_fw.exeOfflineopendir juroots
2025-12-06 17:34:10http://109.230.231.37:9999/silentcleanup_bypass...Offlineopendir juroots

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-06 17:35:31fa49ec614d29893271b15b511a8c36dc3faf8499136cdda1fb8efc220b27491aexe 
2025-12-06 17:35:3176b195b07a76037ca585b760bcf61462e836cc7ae990200e03c1bf7cec9695d5exeRustyStealer
2025-12-06 17:35:3165637e97f6b08780b550ba4d4d66b4aa3f29f2b627953fd9931aff49acd93229exe 
2025-12-06 17:35:30076e5c3ba9b9b940fb4223938698a45387c239db58200d5782283d8414066024exe 
2025-12-06 17:35:254b068261974cfe0001d849f59026f7f3f7d6959c6eb0a87a415cfdb01058ca7cexeRustyStealer
2025-12-06 17:35:2393c53ebc8d1ee19dad41cfb7989ed047136cd80669ec8ba7b0af4016f9123cc1exeRustyStealer
2025-12-06 17:35:231b5d23c3b3a12bfff4b8b2f1f1e3c057b31c7b9a1c9252ac5f61d16ef93dee39exe 
2025-12-06 17:35:06613d4d0f1612686742889e834ebc9ebff6ae021cf81a4c50f66369195ca01899exe 
2025-12-06 17:35:06044a686198878ae1dc4f061c66d0917c7fc2611afe94a1b200b59f4a667aba82exeRustyStealer
2025-12-06 17:35:066c21c70ae517ccf548ac326ac133337b8d12200658ffba5a1f2d7053a34aadc6exe 
2025-12-06 17:35:05883fcdd333eb4252d6f254f9a5a7fb72afe9f8b9dc305e1739517d2493e00b6eexeRustyStealer
2025-12-06 17:35:056a64761a83d244faaa25b559b575c01daa9cd63dc12903e62b42981da9a21d2eexe 
2025-12-06 17:35:044a41291979ce387fd5470ad5afd9db2938669d813f7da7f43dd9f53413457399exeRustyStealer
2025-12-06 17:35:042e6220c3ed90261bd9f0d30cc3684e7c3f763ce524fe7ff49de7bf92870031e9exeRustyStealer
2025-12-06 17:35:034d1fe7b54a0ce9ce2082c167b662ec138b890e3f305e67bdc13a5e9a24708518exe 
2025-12-06 17:35:021252b4a85ea6d33651bbcee4708f0ec14d5915f7ebe9c8de0ffb5bfc6ad8f412exeRustyStealer
2025-12-06 17:35:0262459f33fd9a933799857e537cb3fbfd41b32658cde2a5119cc5a819aecc53caexeRustyStealer
2025-12-06 17:35:01bf020108d0bb8147939fc917736a3110d829b7d59ade54f73a0e54bb1d7d8e37exeRustyStealer
2025-12-06 17:35:00dd7b9d34c04e49362094e526ea408287e440a054ef1f58dc4f1f3ae1e100516fexe 
2025-12-06 17:34:59e25e19888d615b9fb15da4cd7c4cd34dfa53250becff3d621c59c9fa38efdcf3exeRustyStealer
2025-12-06 17:34:5918da271868c434494a68937fa12cb302d37b14849c4c0fc1db4007ac13c5b760exe 
2025-12-06 17:34:5592c4f4b7748f23d6dcd5af43595f34e4bb8e284a85d2c1647b189c1bb59a784aexe 
2025-12-06 17:34:54ad75caddf17f24472c753f1d5fff7fa8ed8a95ce7aad82e6bca8d6bc1ff813d0exe 
2025-12-06 17:34:5190d223b70448d68f7f48397df6a9e57de3a6b389d5d8dc0896be633ca95720f2exeRustyStealer
2025-12-06 17:34:51ba0ffac6927dbc9ea581538291d9eed369277957573ded03d212a99053dbdd1dexe 
2025-12-06 17:34:519cb6adfd5fe0acf5dcdd74d5f721c7955c069b237bc7ca1a1f054083487de573exeRustyStealer
2025-12-06 17:34:51d8090f5058db31956d0503d0e4c9e16504d58623ba481715609a8ff1303d6e72exe  
2025-12-06 17:34:51c4dda7b5c5f6eab49efc86091377ab08275aa951d956a5485665954830d1267eexe 
2025-12-06 17:34:50db60f004b96b5adf202b62ddc57ac866cee1be165539095e31d2e11981b2f84adll 
2025-12-06 17:34:49295f07e8185948de7b0372e918b1f3da8abc0b51f443c3a761af48257491c72dexeRustyStealer
2025-12-06 17:34:45e26e9221f4e9a437716a28c08c5f74c6a2ecae2c47b77091db7d21f36ed2f7d3dll 
2025-12-06 17:34:45353800a0934e6de5d02f660fcde2be3e3b3d3bb70bcff3a157355c77a75cb935exeRustyStealer
2025-12-06 17:34:44cf010c57d465e0bde7a9d5f351aab442bdfff49c393be0bb139185df8a0248ecexeRustyStealer
2025-12-06 17:34:43172258e53b9506a7671deab25d2ad360cd833a4942609f1a4836d305ffe4578bexe 
2025-12-06 17:34:4310eb1fbb2be3a09eefb3d97112e42bb06cf029e6cac2a9fb891b8b89a25c788ddll 
2025-12-06 17:34:429a5fbc975f0c8d292e6b55b74c06a36a2fc2287c0776fa18bb4d9058204bdefdexe 
2025-12-06 17:34:399c79ffd1aa2429e60644252c0f41ef7238da1a8bb781c60e62d021a4b724bb15exe 
2025-12-06 17:34:37072ce701ec0252eeddd6a0501555296bce512a7b90422addbb6d3619ae10f4ffexe 
2025-12-06 17:34:370ec3fca58ef8f0d9f098cd749dd209fccda7cbf68c1eecf836668e5dabd6f3bcexe 
2025-12-06 17:34:35e618c6b7bc2af212f54ed865c84577d2232e50be200925ea8455bd23d549bbe9exeRustyStealer
2025-12-06 17:34:35f8e7e73bf2b26635800a042e7890a35f7376508f288a1ced3d3e12b173c5cb7eexe 
2025-12-06 17:34:346b8e4dba8edc08d2c7ca7da3bd9851e2e00129281786735e724a84fd6f4042d8dll 
2025-12-06 17:34:33091867902dc7e6399ac313774512cff42bc097c4c20d5672e941fe50129af4a2exe 
2025-12-06 17:34:32d942896e56eb6dc83c8788c92e6fe7c57ee419b9b092f3089c74b3f0e181b154exe 
2025-12-06 17:34:305a3b7f08013bcb3d40e4f885167e3aeae3b84ee9c4ac207df0eb83cccd7ac7b3exe 
2025-12-06 17:34:294ad654a8bfcbac5b1816995c2114790a5dec84bf6858e39b15021f5148e84bd6exeRustyStealer
2025-12-06 17:34:29880aa543eedb98847e4345e024c9f1665e2c9df3c379ecc18d9763a46d05b47eexeRustyStealer
2025-12-06 17:34:29821ea5d058f9e714847d05e2a864bf3e713eed145c3ba82fb5c80e3268fe0cd6exeRustyStealer
2025-12-06 17:34:29309bd7b7aa737ede834e498e177a9e0b44b4b46a8666b8182ddc0a4aa283494aexe 
2025-12-06 17:34:28d13b83b603770ae7665f07a215c734db8397465552d389bdd5dbdf0fda17b0f9exeRustyStealer
2025-12-06 17:34:277b7cabb207fcef9a856f86e78a0643bb84cc192f8d93221bde47da1482ddf85dexeRustyStealer
2025-12-06 17:34:274e856041018242c62b3848d63b94c3763beda01648d3139060700c11e9334ad1exe 
2025-12-06 17:34:279cf27311a39f4915ef1ea36f101381c4b3b7fe0eeea43a9739df15c06a563651exeRustyStealer
2025-12-06 17:34:26934c1b89f285a542c6dc5effe2cf5eff303fe54d8d6722dd6d996220fe576b3dexe 
2025-12-06 17:34:262367bc63f02cde7ffd02f928aa971a3b6ffa43a92859969dddd548241f25720edll 
2025-12-06 17:34:265a53149122b6699f13cd897970f1c266ae7fd10fa624e37c41620cec6dbcfac7exeRustyStealer
2025-12-06 17:34:26d73c4f127c5c0a7f9bf0f398e95dd55c7e8f6f6a5783c8cb314bd99c2d1c9802exeRustyStealer
2025-12-06 17:34:25c9992209339d05dd934b99298cf35da7ac9d152c6d0df200258d636bcfc7de78exe 
2025-12-06 17:34:249283570c0ad823a6dba85d640d2fdddf4a0da091ec2f063ec5bc4cdac50d84d1dll 
2025-12-06 17:34:2363750abb5c17273ee28f64680c64f94451907c4b874a433b30401cb6d7f78b8bdll 
2025-12-06 17:34:225e46b08b08cf4a2722459f48f9ef18f63d2c824bfa6798e254dac4f99b1eec49exe 
2025-12-06 17:34:2261c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1exe MimiKatz
2025-12-06 17:34:22e71240f26af1052172b5864cdddb78fcb990d7a96d53b7d22d19f5dfccdf9012dll 
2025-12-06 17:34:2239f6a1e340dbbcbb6285126eea7d2f083aec11a72f5bf7f82922abdfc556ea64exe 
2025-12-06 17:34:21216c3ea5d784bd15587809d664a5849ab32ebcafccd553598402c70cd21719aczip 
2025-12-06 17:34:211487e05055c2b8488094e9b7d90cfe47d91704fe07be25853b56b85a6f995339dll 
2025-12-06 17:34:17ac9c44a3f4bedb921c58d0182f24777f035d60f338e265a08ca18097529d1040dll 
2025-12-06 17:34:1747ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428exe 
2025-12-06 17:34:1764c924b671ac30fb16981fe3473e6241f41bb8ddd39d342d279f2c5ecba65fc2exeRansomware.BlackMatter
2025-12-06 17:34:163953a9216581adbb81e5761646c5b6dee88929c079913403cf717b566db8256ddll 
2025-12-06 17:34:15b235e7660cfa48ef9f2676161eebcdc14992a63dbff5fd40e5609a49898f642fdll 
2025-12-06 17:34:159c79ffd1aa2429e60644252c0f41ef7238da1a8bb781c60e62d021a4b724bb15exe 
2025-12-06 17:34:15637be4d4df565ad9299be22e19deacaa343f05d56fb9ea0a201fb012ac8f4df9exeRansomware.LockBit
2025-12-06 17:34:12f61055630f6ec93652be25700bc48b6db997560cf0de1f7b3132ba7206603688exe