URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 139.99.75.86
Firstseen:2026-04-11 07:28:05 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-11 07:28:07 139.99.75.86Not listedAS16276 OVH- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-11 07:28:07http://139.99.75.86/Kharon_https_443.x64.svc.exeOffline139-99-75-86 ua-wget BlinkzSec
2026-04-11 07:28:07http://139.99.75.86/Kharon_https_443.x64.exeOffline139-99-75-86 ua-wget BlinkzSec
2026-04-11 07:28:07http://139.99.75.86/Kharon_https_443.x64.dllOffline139-99-75-86 ua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-11 07:28:078e3f7307deb54940e8bec734cd1760f9cfbe07d1f1bc33135cbaaa4959de43f3exe 
2026-04-11 07:28:071c7cdc98e74642be9e2e55a7766ea711501b15dd30af3bb9686b57d1ad7dd3c7dll 
2026-04-11 07:28:066a20a6ed6385d19d401300ee00c516528bda7373fbbcd90e23b018bc020c2d6dexe