URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 141.98.6.91
Firstseen:2023-10-24 05:55:06 UTC
Total malware sites :27
Online malware sites :0 (0%)
Offline Malware sites :27 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-10-24 05:55:08 141.98.6.91Not listedAS213702 QWINS-LTD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-10-30 06:53:08http://141.98.6.91/1903/1/KEW.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-30 06:53:05http://141.98.6.91/1903/1/HTMLIEsearchHistory.vbsOfflineopendir vbs abuse_ch
2023-10-30 06:53:05http://141.98.6.91/1903/1/k/HTMLhistoryClearner...OfflineAgentTesla ext doc opendir abuse_ch
2023-10-30 06:52:06http://141.98.6.91/1903/2/MAW.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-30 06:52:05http://141.98.6.91/1903/2/HTMLIEcontentHistory.vbsOfflineopendir vbs abuse_ch
2023-10-30 06:52:04http://141.98.6.91/1903/2/m/HTMLHisotoryCleaner...OfflineAgentTesla ext doc opendir abuse_ch
2023-10-27 15:42:07http://141.98.6.91/38/HDV.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-27 15:41:06http://141.98.6.91/38/HTMLDesginbrowser.vbsOfflineAgentTesla ext opendir vbs abuse_ch
2023-10-27 15:41:06http://141.98.6.91/38/html/HTMLDesginBrowserInt...OfflineAgentTesla ext doc opendir abuse_ch
2023-10-27 15:40:09http://141.98.6.91/39/KLV.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-27 15:40:07http://141.98.6.91/39/HTMLIEbrowserHistory.vbsOfflineAgentTesla ext opendir vbs abuse_ch
2023-10-27 15:40:07http://141.98.6.91/39/www/HTMLIEbrowserHistoryC...OfflineAgentTesla ext doc opendir abuse_ch
2023-10-27 15:39:05http://141.98.6.91/htms/HTMLIEBrowserChatHistor...OfflineAgentTesla ext doc opendir abuse_ch
2023-10-24 06:08:05http://141.98.6.91/2010/SAN.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-24 06:08:04http://141.98.6.91/2010/MAH.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-24 06:07:07http://141.98.6.91/2150/1/MHM.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-24 06:07:07http://141.98.6.91/2150/2/SMH.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-24 06:07:05http://141.98.6.91/2150/2/SMH.vbsOfflineopendir vbs abuse_ch
2023-10-24 06:07:05http://141.98.6.91/2150/2/HTMLCacheCentos.docOfflinedoc opendir abuse_ch
2023-10-24 06:02:06http://141.98.6.91/2150/1/mhs.vbsOfflineopendir vbs zgRAT abuse_ch
2023-10-24 06:02:06http://141.98.6.91/2010/1/MAH.vbsOfflineopendir vbs zgRAT abuse_ch
2023-10-24 06:02:06http://141.98.6.91/2150/1/HTMLCacheCentos.dOCOfflinedoc opendir zgRAT abuse_ch
2023-10-24 06:02:06http://141.98.6.91/2010/1/HTMLprofile.dOCOfflinedoc opendir zgRAT abuse_ch
2023-10-24 06:01:05http://141.98.6.91/2010/2/san.vbsOfflineascii opendir vbs zgRAT abuse_ch
2023-10-24 06:01:04http://141.98.6.91/2010/2/HTMLprofile.docOfflinedoc opendir abuse_ch
2023-10-24 05:55:09http://141.98.6.91/windows/HNB.txtOfflineAgentTesla ext ascii Encoded opendir abuse_ch
2023-10-24 05:55:08http://141.98.6.91/windows/HTMLobject.vbsOfflinerat vbs zgRAT abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-10-30 06:53:08ee5f9db434fd074aec31851dec2286f8f49061afd2f62e60bf34102e7a04f9f9txt AgentTesla
2023-10-30 06:53:05eafb3cea4da435ac46bda9d56ab4b7624a0b0c3d848496d169a1b00b8eba0e03unknown  
2023-10-30 06:53:05a7f65b6ed848a8ce8f8486d26918ab440e442f0acc938d0513f0390381d80258unknown  
2023-10-30 06:52:062974668ff6af372cfa139f9eedde01bdda46fd1d019b6a80a6027b15e1876a01txt AgentTesla
2023-10-30 06:52:0576a73ec52afc9b6ba0596388abba0ace5eb64779c0154fd976c521c470d53f14unknown  
2023-10-30 06:52:048266d8ebf0586f5e43faaff0ded41e5da85478b72844bbd505bf6c08a711ab22unknown  
2023-10-27 15:42:070871bc2bf47b7d07ab61536800b98ecf40c64ee3a5f4949a8608d6120d68a63btxt AgentTesla
2023-10-27 15:41:06f1098c69adab031391ddc2a53df8af450f1a0c908fed813e6bc962d30a56599bunknown  
2023-10-27 15:41:067fde513a7dd89278194c6af83964d46b3af013612815148974b62ffc50152ea2unknown  
2023-10-27 15:40:0962b3844748bff8b1fa934e13db83d640105533c677dad0a577ab42035f547c11txt AgentTesla
2023-10-27 15:40:0769749b30b56c0c82fcd8c066a9ce23c140d7a0f07e5270148b4bdc242f888154unknown  
2023-10-27 15:40:070e39d0f237fd2a7c2cd716f403abc719a9f061d7278e403978029b4e8ddacedcunknown  
2023-10-27 15:39:050e39d0f237fd2a7c2cd716f403abc719a9f061d7278e403978029b4e8ddacedcunknown  
2023-10-25 01:14:034f799501a3f411314a5a678c5c6e45b8ebcb16aa3b7e7d9a1996e0eda8bc6029unknown  
2023-10-24 06:08:05744697b9e83e99c851607885289e7f49d50aac23f4de1d274f1d2deaca73ec79txt AgentTesla
2023-10-24 06:08:0436e2f0ba096fbef71afcfb6d866ba6f8cb6ecf1a2286213035ae80617af8960etxt AgentTesla
2023-10-24 06:07:0736e2f0ba096fbef71afcfb6d866ba6f8cb6ecf1a2286213035ae80617af8960etxt AgentTesla
2023-10-24 06:07:07744697b9e83e99c851607885289e7f49d50aac23f4de1d274f1d2deaca73ec79txt AgentTesla
2023-10-24 06:07:05b41044bd2bd4b63bf6022de305bfc2845bc32ebf05c9f91746751c38f7faf1beunknown  
2023-10-24 06:07:05e5a0f3a0bb65321657c98422f2de177762f70bffe8453b187cf957be71420f7dunknown  
2023-10-24 06:02:0661f9f532d6d55a110ec6508d4e343ecdf5e154d02eb67661c1669907ce45db42unknown  
2023-10-24 06:02:0615082cbabfd0ab61016758924c9e1f3925632c80915374d2f6671c4c77e89e86unknown  
2023-10-24 06:02:06d0755665e3d25783a229d9f872e08a4da8d5f0455e72f7330423de7f09d6de67unknown  
2023-10-24 06:02:05d98f2e4d241244265a3618366e4e9079314fc4b8235c599423d2f57dabd0e0c7unknown  
2023-10-24 06:01:057729e13ec6f9b7dfdb8e14678e7d86d212a468f441c550f9f7f4c9b5370e2dd3unknown  
2023-10-24 06:01:0458c271cee53f372e24bff45fa720c2ec7628ae8a2840c16ce74d13f417eb47ceunknown  
2023-10-24 05:55:09ef9d53d0c4be6597aac7ca9602f71d37c35fe736949cee53d608375fa5e3e2c6txt AgentTesla
2023-10-24 05:55:07b4f6b87e41f69f8f570148bab3fc32c6caa76c583d4f13e5a824ed87c9fbe585unknown