URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 13.55.233.37
Firstseen:2022-05-24 06:53:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-05-24 06:53:07 13.55.233.37ec2-13-55-233-37.ap-southeast-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- AUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-07 15:25:36http://13.55.233.37/mscloud11/csrss.exeOfflineAnonymous
2022-07-07 15:25:35http://13.55.233.37/ms365cloud__/csrss.exeOfflineAnonymous
2022-05-24 07:28:07http://13.55.233.37/data2cloud/csrss.exeOffline32 exe Formbook ext zbetcheckin
2022-05-24 06:53:07http://13.55.233.37/diskoncloud/csrss.exeOfflineexe Formbook ext opendir zgRAT abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-05-24 14:34:34c7f49a99084b69880eb19687ec2e2386fef8d0c13e16e9ab9755e11e07bbadf3exe zgRAT
2022-05-24 07:28:07a1726f588e0d03a3522f60d177448bfd7a5355133cfd725be8198c1cca68b51cexeFormbook
2022-05-24 06:53:07a5d049127c3a6a9f312abcf4ed2f8ee10f982b0f8e85e740fb166f70b67620ddexeFormbook