URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 124.220.35.63
Firstseen:2023-03-07 08:03:03 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-07 08:03:15 124.220.35.63Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-04-01 04:55:08http://124.220.35.63/666.exeOffline32 exe Gh0stRAT zbetcheckin
2023-03-31 16:04:00http://124.220.35.63/110.exeOfflineexe Gh0stRAT sality abuse_ch
2023-03-31 15:56:05http://124.220.35.63/bwj.exeOfflineexe abuse_ch
2023-03-31 15:55:23http://124.220.35.63/380.exeOfflineexe Gh0stRAT abuse_ch
2023-03-20 08:57:05http://124.220.35.63/laoxiang.exeOfflineexe abuse_ch
2023-03-14 07:52:29http://124.220.35.63/xinxin.exeOffline32 exe Gh0stRAT sality zbetcheckin
2023-03-14 06:13:10http://124.220.35.63/669.exeOffline32 exe Gh0stRAT zbetcheckin
2023-03-14 06:13:10http://124.220.35.63/niubi.exeOffline32 exe Gh0stRAT zbetcheckin
2023-03-14 05:20:10http://124.220.35.63/9666.exeOffline32 exe Gh0stRAT zbetcheckin
2023-03-14 04:41:13http://124.220.35.63/103.exeOffline32 exe Gh0stRAT zbetcheckin
2023-03-07 08:15:47http://124.220.35.63/wait1.exeOfflineGh0stRAT JAMESWT_MHT
2023-03-07 08:15:23http://124.220.35.63/KKSEZ1.exeOfflineGh0stRAT JAMESWT_MHT
2023-03-07 08:15:20http://124.220.35.63/diyige.exeOfflineGh0stRAT younglotus JAMESWT_MHT
2023-03-07 08:15:19http://124.220.35.63/zckop.exeOfflineyounglotus JAMESWT_MHT
2023-03-07 08:15:16http://124.220.35.63/358.exeOfflineyounglotus JAMESWT_MHT
2023-03-07 08:03:15http://124.220.35.63/zmp2.exeOfflineyounglotus JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-04-12 07:56:12197b9147b1d40aefd4f75d394a04520d2873e9df42a5782df7df31a88c2ae150exe Sality
2023-04-11 13:02:274d11a73e4036a2ed5e797908a3fb3bd59e523b18c6afc41d2b56e2dc213de186exe  
2023-04-11 01:20:1420ad1e6af5c86cb19ced3387f0a7928d98d5b62537d525d1a63e3ecd4a039bbaexeSality
2023-04-03 18:06:01012e401eb5eb74c9aa7d2a3d6bd6a3d367786385280c2f705a85263b8f261c67exe Gh0stRAT
2023-04-03 13:21:409b75ee52e914ccdaf0afa4890860bd298da7888a521808bdcacf4e73044a3c43exe  
2023-04-03 12:51:36d4b3679a4242f7aaaebeb673fdbd9f5f4bce891d93fc64b22c55bd9861ba55f4exe Gh0stRAT
2023-04-03 07:42:421c2ac0a191ff07118f25672a65b705cdeecb78538b2be9b412043d499176f2b6exe  
2023-04-03 04:56:40458990c9dfdd1d3c1876b71542fccb804cb238e1835a072f29f655543019ad7fexe  
2023-04-03 03:57:56dc4f203ee5df59eb9a271b10623df67daeadec8e43dcc12daa8a6fa0b4f1606bexe  
2023-04-03 01:25:463d13ba2eeb19538cf0631877390631a0d02a7add98c9d37782ca89e9bf7305d1exe  
2023-04-02 21:36:22e376d08055ae263ba060949eba2718d2023a80c16de49471ad3d2d87a124ed50exe  
2023-04-02 18:16:4035a0b8e272e38ffe26e3b8d75a231dcee86e1ea1b53848a5584783ee4db30236exe  
2023-04-02 11:05:32005bff91c7c3ca88fc794d00d4882a634276c85b506679624b3b51a6a1aec6d1exe 
2023-04-01 14:46:57a72ed711b79d16693eb00366d850efd707d1ca01abdc1c2fae072b7b67440f0bexe  
2023-04-01 08:36:029454a53dcc4fc62ef06c8ea76043057fa4e688f8d2208d837bad89f2374069ceexe  
2023-04-01 04:55:08d8f5ab16727edf68166c9f7973dcf87d3a563fefcb013154ccbd81367677a2cdexeGh0stRAT
2023-03-31 19:58:306a267008dc7b95a1bcade4a19072e2df29af9f6bbd372d9e5444540260a10d7aexe  
2023-03-31 16:04:0020f4b006007defc2e71a4a3bc6ffe0cdbb5ed6f34c4e15e95d85a7cb60a76286exeGh0stRAT
2023-03-31 15:56:0537a5d7960b09d3f0ec4c8d39203ce285a9ced3c70c3e3fbd5c6f3f21678bdec4exe 
2023-03-31 15:55:23cc68b5edae8acaaf394ae0b92b6199f83630b9d66ba60152f0db0aa849cb0eceexeGh0stRAT
2023-03-20 08:57:051ef14f23c1c3fad652b81376340e8882a942b27052f85e96040067fc0ac4cd5aexe 
2023-03-14 07:52:29d46dbbb40bf11bda9b1aa74d9d2550a73ab0ae6008270c2c541153cd4974a3ddexeGh0stRAT
2023-03-14 06:13:104e90491d7bfcb50079a2fc9795b8ae9c4bd9ee5b26913b075ea248f953c6b910exeGh0stRAT
2023-03-14 06:13:1071a0f84fc97d3ea8ecdc9dc19e058fe994e3cecf826f3db462c4995d8ee6dacbexeGh0stRAT
2023-03-14 05:20:107d147fa016e7218fcf60c76d2688a100e83fbb580f3c954d55e08d2c7b0b5a14exeGh0stRAT
2023-03-14 04:41:131f3194c5d2f7de0505f5a5a6d219f217cd5526ef7c9f8cd2d163887176572825exeGh0stRAT
2023-03-13 05:33:4035974873a02e6bb71b7d10a3c280e9bed19f656d094741c991475dab91099620exeGh0stRAT
2023-03-07 08:15:47a853b17061786737988e904c7cca3c808f5a74ea3bb6d9c624ae71bd08ea40adexeGh0stRAT
2023-03-07 08:15:23a8f59998bb89d7563e5dcadd2a7f23b86c8e643203cc921abe3450fe80348a0bexeGh0stRAT
2023-03-07 08:15:197fcde90bf1f4e6ec55e94000936f6264264990f16511c5fae5a2faaefd8400f7exeYoungLotus
2023-03-07 08:15:19167a12055852953ff43bda213ecc524fd8af28f6613ffa9225a6c3259e079357exeYoungLotus
2023-03-07 08:15:166ceb50da4275db929de139517ee96a5617ca2a8dead8db120d4f43a467f2fbf5exeYoungLotus
2023-03-07 08:03:09c5bbffaaa02f6289977ee6ba6f2684953114cebc79f3e3e6aca7ca301a87a117exeYoungLotus