URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 135.125.177.94
Firstseen:2023-05-15 17:19:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-05-15 17:19:10 135.125.177.94ip94.ip-135-125-177.euNot listedAS16276 OVH- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-05-15 17:37:04http://135.125.177.94/aQ2nHl74yJrc6dw8N.datOfflinedll geofenced obama263 Qakbot ext Quakbot ext USA Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-09-18 07:59:08694608d38b05b9e2af7f3140545498baede355f91ee5a877928bec4009dce805html 
2023-06-14 23:38:36db407931cdffa1c8de6a0b02a67989478cdaab0af009fc85ea6836df39a2f287dll Quakbot