URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 111.90.148.23
Firstseen:2020-07-13 02:51:02 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-07-13 02:51:08 111.90.148.23server115899.webkevlar.netNot listedAS45839 SHINJIRU-MY-AS-AP- MYyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-13 02:51:36http://111.90.148.23/100720.docOffline p5yb34m
2020-07-13 02:51:27http://111.90.148.23/svchosts.exeOfflineAveMariaRAT ext exe p5yb34m
2020-07-13 02:51:22http://111.90.148.23/Documento_importante.exeOfflineAveMariaRAT ext exe p5yb34m
2020-07-13 02:51:08http://111.90.148.23/Certificado_Autenticaci%c3...OfflineAveMariaRAT ext exe p5yb34m

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-13 02:51:36338172dfc1bbd6a1ce8ba7de2cf1f88d1d47f8f4dc2b386d25f9b1955718d148rtf  
2020-07-13 02:51:27dd925e2203d772228a9faada1dd3b1672a9a5e3bccaffdaf3cd076bc7b462586exe AveMariaRAT
2020-07-13 02:51:22922be6acb1365bac828b5493a4ba1a5fd0d214a5273f39bfbaf932d80c9b5a75exeAveMariaRAT
2020-07-13 02:51:08419fdd95959d3b4a086ad9009775e08bde4867593bffc22e05e19d89606698f4exeAveMariaRAT