URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 112.18.10.80
Firstseen:2025-06-11 04:17:04 UTC
Total malware sites :5
Online malware sites :2 (40%)
Offline Malware sites :3 (60%)
Newest active malware site :2025-06-17 21:17:20 UTC
Oldest active malware site :2025-06-11 04:17:11 UTC (Age: 11 months, 20 days, 12 hours, 45 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-11 04:17:11 112.18.10.80Not listedAS9808 CHINAMOBILE-CN- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-06-17 21:17:20http://112.18.10.80:7001/gg.apkOnlineopendir Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-06 04:56:3913b3e078fe086e5a4ad5a98251289457912f301092ee39ddf094073e8193c93azip  
2025-08-12 18:19:015c6552f684eaa87e0e8830eabe68e2a4236e0eb77af8cfbb11308449394e0f0dzip  
2025-08-12 06:37:315128eb4d9896a9ae826389950e3f025b071132bcca64c13b7508016a823e2fabzip  
2025-06-17 21:18:121d2a9bde01377b607abb7e2a2c9f9e172cb3cb7049fd3f99e49b7b47c048dbd8zip  
2025-06-17 21:17:197028f8a2ad6119e8cfd429521601cdb278b51cdf3ee81411114f4eac1431fa85zip  
2025-06-11 04:17:1092e5e9eb5a50fd2a61238447e2206e8e5d9a492352f278628dec8c934031f6d3sh