🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 119.28.78.133
Firstseen:2024-09-15 00:27:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-09-15 00:27:07 119.28.78.133Not listedAS132203 TENCENT-NET-AP-CN- HKyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-09-15 00:28:20http://119.28.78.133/rootOfflineCoinMiner elf xmrig NDA0E
2024-09-15 00:27:34http://119.28.78.133/ngrok.exeOfflineexe frp ngrok opendir NDA0E
2024-09-15 00:27:08http://119.28.78.133/1.exeOfflineAdware.Neoreklami exe KillAV opendir NDA0E
2024-09-15 00:27:07http://119.28.78.133/LB3.exeOfflineBlackMatter Darkside exe lockbit opendir NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-09-15 00:28:1901c6c81abf1206caf6c4004bae8c4999624228c8b1ce7514503e4150c10c21b5elf  
2024-09-15 00:27:349b18df84a96f68f8726d26bc661a86a984d8fda4e5e8c2641ad91d103d028b05exeFRP
2024-09-15 00:27:08704ebc20fe0c7678a2b73d97ba6ad2945ece3a7d35ba0e0a394b629570af00caexeAdware.Neoreklami
2024-09-15 00:27:07105912c9995a1d718c5442349d2cc4bb99426f75ff34554cdfd9a7272eeca398exeRansomware.LockBit