URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 110.159.139.75
Firstseen:2020-02-18 15:06:02 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-02-18 15:06:05 110.159.139.7575.139.159.110.tm-hsbb.tm.net.myNot listedAS4788 TTSSB-MY- MYyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-02-18 15:06:05http://110.159.139.75:32841/.iOfflineelf hajime zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-03-03 10:44:02259fa722137526403bce9409f9b5da6139f952d69ddbbc84a9bc1737bb73dbf7elf 
2020-02-21 15:20:40d887c82414989b181a656b52a011907da0a7252a87436c2a903dc4c1004bcdbaelf  
2020-02-18 15:20:111c483bbea1c4d044786f0a69c6df1632581d0a97e5e0a372b2ac02b22ee5ac4belf  
2020-02-18 15:06:05a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3elfHajime