URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 113.52.134.114
Firstseen:2023-12-14 07:26:05 UTC
Total malware sites :24
Online malware sites :0 (0%)
Offline Malware sites :24 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-12-14 07:26:13 113.52.134.114113.52.134.114.layerdns.cloudNot listedAS133380 LAYER-AS- HKyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-12-14 07:26:49http://113.52.134.114/ToDesk_Setup.exeOfflineHavoc abus3reports
2023-12-14 07:26:18http://113.52.134.114/fol5.exeOfflineHavoc abus3reports
2023-12-14 07:26:17http://113.52.134.114/zil5.exeOfflineHavoc abus3reports
2023-12-14 07:26:17http://113.52.134.114/ekk5.exeOfflineHavoc abus3reports
2023-12-14 07:26:17http://113.52.134.114/wai5.exeOfflineHavoc abus3reports
2023-12-14 07:26:16http://113.52.134.114/ekk3.exeOfflineHavoc abus3reports
2023-12-14 07:26:16http://113.52.134.114/ekk2.exeOfflineHavoc abus3reports
2023-12-14 07:26:16http://113.52.134.114/fol1.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/ekk4.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/wai2.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/zil3.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/fol4.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/zil1.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/wai3.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/wai1.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/fol3.exeOfflineHavoc abus3reports
2023-12-14 07:26:15http://113.52.134.114/wai4.exeOfflineHavoc abus3reports
2023-12-14 07:26:14http://113.52.134.114/zil2.exeOfflineHavoc abus3reports
2023-12-14 07:26:14http://113.52.134.114/demon.exeOfflineHavoc abus3reports
2023-12-14 07:26:14http://113.52.134.114/zil4.exeOfflineHavoc abus3reports
2023-12-14 07:26:13http://113.52.134.114/fol2.exeOfflineHavoc abus3reports
2023-12-14 07:26:13http://113.52.134.114/nide.binOfflineHavoc abus3reports
2023-12-14 07:26:13http://113.52.134.114/ekk1.exeOfflineHavoc abus3reports
2023-12-14 07:26:13http://113.52.134.114/test.binOfflineHavoc abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-14 07:26:49d245312c2b0a29de60324ec5521d87e1ed3ce870b0b393d32d791864e97e31e3exe  
2023-12-14 07:26:188b25d00b2d476a122c869e59bbc3f0635c36d59066a12ee7a054563602794a89exeHavoc
2023-12-14 07:26:17a9180fb79d272c7f05692d692beb8436aa131fde1c4390e6942c502b6333e6c6exeHavoc
2023-12-14 07:26:17e5678edaa33ccb76eb24df35029b65d60c36908113067f66023c3fc548970036exeHavoc
2023-12-14 07:26:17785b9a0624ffcc5f9c12c6c5cce4e474ad1d59311a2e39701529dc10ca2a0bbeexeHavoc
2023-12-14 07:26:1641efbb27cec78b72e56b469c635fd26dd92bab122220dd77791230f3aa9ca8b3exeHavoc
2023-12-14 07:26:16048cdec89a97f5751c55d1b458fd0ee81be632f23a6df3aaac33172a1dad2289exe 
2023-12-14 07:26:165da64b62dff944e2b9bb3ca115832f88caedf52afa3f045ba1199d3da29212acexeHavoc
2023-12-14 07:26:159344be219cdab18c4f6148c8e47330e3fab688934dffd0fbc17317638eba4d0cexeHavoc
2023-12-14 07:26:15206636cc3e595d020c3fb557356566da123ee9a9f59e02c7fbf5ac32acfb80bbexe 
2023-12-14 07:26:15e2762ea7c59520a1a989cb3d6798b00ffba323e82a5db2cd0f778573feddfa60exeHavoc
2023-12-14 07:26:158c0be5f83ceabd02114ffe1eacfe59ef011bc09fe08a4eb22c6cc14fbd80bce7exeHavoc
2023-12-14 07:26:1598d192e5117e1956c22bdbd64397f7702415e2a2a90a077d4c9fde60a13caf26exeHavoc
2023-12-14 07:26:153308965802e98b741b4746e70b353c4e4b264d624ac7d9bfba531f90caa30c73exeHavoc
2023-12-14 07:26:1515bffc5a28e2a4b1720d3da53d64576223e50bd587066c64b53f4931cfa3fd3eexeHavoc
2023-12-14 07:26:157a3f54e7c4f16bff7c2b1b93b0d5b1c226ec43f4a97f5ad4db972fb96f2a1e19exeHavoc
2023-12-14 07:26:14575343d1c8d28e40312688587eaa87035821c94d854b80fce362bd462b1cf874exe 
2023-12-14 07:26:14bb466b4f503c00221425ef7e6286f5b5dfc0e6da68bf4653ff5e9c78869ce059exeHavoc
2023-12-14 07:26:133aad93d064d729509e499014d59f0c5b3d290f5d130bcba94e2d8f069d8881ddexeHavoc
2023-12-14 07:26:132af5538e8958c1197321a8b5d7c749876dfef2c2b88df2dca1bb9f8ca3325be6exeHavoc
2023-12-14 07:26:13380fecae465a8ee285b90765b7a69d6cc1d5f62ee7503d3517f584c8f2f566a6unknown  
2023-12-14 07:26:128851a3faab94a5c68217fa4de968cc0e82506cba6bd17d779bc5c6f320d4a7a7exeHavoc
2023-12-14 07:26:117c6bd535738cf0b1a2e8c259e52e271ee2199e22ae50ce311ff0809e237548d1exeHavoc
2023-12-14 07:26:1018959e1a03cb8f8222024c14453d664e650e5f3e865f2ab1cdd5d8227b68de47unknown