URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 115.29.189.57
Firstseen:2021-02-25 10:06:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-02-25 10:06:05 115.29.189.57Not listedAS37963 ALIBABA-CN-NET- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-02-25 10:06:24http://115.29.189.57:2233/1.exeOfflineCoinMiner.XMRig exe hfs abuse_ch
2021-02-25 10:06:06http://115.29.189.57:2233/whoami.dllOfflinedll hfs Redosdru ext abuse_ch
2021-02-25 10:06:05http://115.29.189.57:2233/123.exeOfflineexe hfs Redosdru ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-02-25 16:03:31a2b2c670a6f1fd4d660f5c7c1e1e66518d1521496b6bd1b794254f1c5e47cf48exe  
2021-02-25 12:51:144ff6ab539d2be6f34f913bce3f8616b4b2c18d9bb7628c9914cc489c7268a02fexe 
2021-02-25 10:06:24ffd134c643a96d41f3e2e4cdbe7b7a5d2d3e0335921e49618d6b3f9ee896a948exeCoinMiner.XMRig
2021-02-25 10:06:063394755e45b6cba8fd63160512a847533de89cd88bd8eec3251623e85f67e987unknown  
2021-02-25 10:06:0461ecfd8948a9bda08bac231b30ea70884e215e6a66af434db3a6af68810252adexe Redosdru