URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 111.230.72.242
Firstseen:2024-07-08 16:34:05 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-07-08 16:34:06 111.230.72.242Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-08 16:38:07http://111.230.72.242/frpc.exeOfflinecobaltstrike-c2 exe frp abus3reports
2024-07-08 16:37:52http://111.230.72.242/frp-c.exeOfflinecobaltstrike-c2 exe frp abus3reports
2024-07-08 16:37:45http://111.230.72.242/fr.exeOfflinecobaltstrike-c2 exe frp abus3reports
2024-07-08 16:37:21http://111.230.72.242/smz.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:37:16http://111.230.72.242/fscan32.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:37:07http://111.230.72.242/fscan_win03.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:36:07http://111.230.72.242/bycshttp.exeOfflineCobaltStrike ext cobaltstrike-c2 exe abus3reports
2024-07-08 16:35:48http://111.230.72.242/netspy.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:52http://111.230.72.242/GotoHTTP.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:21http://111.230.72.242/xl.jspOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:11http://111.230.72.242/beacon.exeOfflineCobaltStrike ext cobaltstrike-c2 exe abus3reports
2024-07-08 16:34:11http://111.230.72.242/nc.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:10http://111.230.72.242/nc1.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:10http://111.230.72.242/frpc.iniOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:08http://111.230.72.242/msf.exeOfflinecobaltstrike-c2 exe abus3reports
2024-07-08 16:34:07http://111.230.72.242/artifact.exeOfflineCobalt strike ext cobaltstrike-c2 exe abus3reports
2024-07-08 16:34:06http://111.230.72.242/Offlinecobaltstrike-c2 exe abus3reports