URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 122.51.183.116
Firstseen:2024-07-04 08:10:15 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-07-04 08:10:26 122.51.183.116Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-11-02 14:35:17https://122.51.183.116/svchost.exeOfflineexe Gh0stRAT abus3reports
2024-09-15 18:00:15http://122.51.183.116:1234/svchost.exeOfflineexe Gh0stRAT opendir DaveLikesMalwre
2024-07-04 08:10:26https://122.51.183.116/%e5%a4%8d%e5%8f%a4%e6%94...OfflineGh0stRAT lontze7
2024-07-04 08:10:26https://122.51.183.116/svohost.exeOfflineGh0stRAT lontze7

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-11-02 14:35:1736ca73fac0f3955bf525b4c7c72f1a5630be6f66f5726801ca3976829f8ce94bexeGh0stRAT
2024-09-15 18:00:1536ca73fac0f3955bf525b4c7c72f1a5630be6f66f5726801ca3976829f8ce94bexeGh0stRAT
2024-07-04 08:10:256c82b1e394b7da24e62f03c745c0ceb907f49f0a43d032f9b3bc53ef8179e7a2exeGh0stRAT
2024-07-04 08:10:2136ca73fac0f3955bf525b4c7c72f1a5630be6f66f5726801ca3976829f8ce94bexeGh0stRAT