URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 146.70.143.176
Firstseen:2022-10-19 05:59:04 UTC
Total malware sites :34
Online malware sites :0 (0%)
Offline Malware sites :34 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-19 05:59:05 146.70.143.176Not listedAS9009 M247- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-19 06:01:06http://146.70.143.176/MAL/bin/fakenative/NITRO.exeOfflineexe opendir abuse_ch
2022-10-19 06:01:05http://146.70.143.176/MAL/bin/dream/AOU.exeOfflineexe opendir QuasarRAT ext abuse_ch
2022-10-19 06:01:05http://146.70.143.176/MAL/bin/virtulazation/Nit...Offlineexe opendir abuse_ch
2022-10-19 06:01:05http://146.70.143.176/MAL/bin/dream/net32.exeOfflineexe opendir abuse_ch
2022-10-19 06:01:05http://146.70.143.176/MAL/bin/virtulazation/nit...Offlineexe opendir abuse_ch
2022-10-19 06:01:05http://146.70.143.176/MAL/bin/dream/net64.exeOfflineAdware.Techsnab exe opendir abuse_ch
2022-10-19 06:01:04http://146.70.143.176/MAL/bin/dream/nativenoadm...Offlineexe opendir abuse_ch
2022-10-19 06:01:04http://146.70.143.176/MAL/bin/dream/native32.exeOfflineexe opendir QuasarRAT ext abuse_ch
2022-10-19 06:01:04http://146.70.143.176/MAL/bin/virtulazation/Dar...Offlineexe opendir PlagueBot abuse_ch
2022-10-19 06:00:10http://146.70.143.176/MAL/bin/FileHistory.exeOfflineexe opendir QuasarRAT ext abuse_ch
2022-10-19 06:00:09http://146.70.143.176/MAL/bin/cryptedfile.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:08http://146.70.143.176/MAL/bin/AOU.msiOfflinemsi opendir abuse_ch
2022-10-19 06:00:07http://146.70.143.176/MAL/bin/NITRO.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:06http://146.70.143.176/MAL/bin/Crypted.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:06http://146.70.143.176/MAL/bin/New%20Project%201...Offlineexe opendir abuse_ch
2022-10-19 06:00:05http://146.70.143.176/MAL/goodobf/nitro.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:05http://146.70.143.176/MAL/bin/AOU.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:05http://146.70.143.176/MAL/goodobf/nitro64.exeOfflineexe opendir abuse_ch
2022-10-19 06:00:04http://146.70.143.176/MAL/bin/DisDefDown.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:09http://146.70.143.176/MAL/blmkgrp.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:07http://146.70.143.176/MAL/Server.exeOfflineexe opendir PlagueBot abuse_ch
2022-10-19 05:59:06http://146.70.143.176/MAL/orc.exeOfflineexe opendir orcusrat abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/orc.ps1Offlineascii opendir ps1 abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/2022files.zipOfflineopendir zip abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/disdef.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/drpone.ps1Offlineascii opendir ps1 abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/nitro64.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/drpone.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/2022files.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/AOU.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/demon.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/nitro64.vbsOfflineascii opendir vbs abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/nitro.exeOfflineexe opendir abuse_ch
2022-10-19 05:59:05http://146.70.143.176/MAL/AOU.docOfflinedoc opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-19 06:44:14ec21f3f70c1fd028436ab2e68ebccf90860011e08c71e26f70d3170bb9f0f2f4exe  
2022-10-19 06:01:06a61b8fe555850732d328805736d0fc882191ac9bac7c61df5777850237d12f39exe  
2022-10-19 06:01:05bf45d7d41cf421da9cf70d0616d2e2ed599829a190fbfc6b6fd1170cecc5657aexeQuasarRAT
2022-10-19 06:01:0516a21b4779671bb1ec7bcb26a9f8c6b8ebffacc5a0b4c05468a9b340ec5aa15cexe  
2022-10-19 06:01:054e441dcbac9fd22e565fb19a74810c63307870541228520b4eb43bd1bc764e95exe  
2022-10-19 06:01:0545255ed1f25b15b07ec7986089d80327884cb9775fdf5ae764deffb3d3901122exe 
2022-10-19 06:01:0500a7b6cbeb76f66bec8afb8de1fccc230d0dd2a16211fa9ca1d93e7f8cb462d1exe Adware.Techsnab
2022-10-19 06:01:04aa9deb2a1d67a4e73e7419b86535f1197dc8b7ffebdd392fb35f7c10d92b9dc1exeQuasarRAT
2022-10-19 06:01:041bbc88529caf638cf60f3a41ce43584a520570787f0bba8311bc7d2f08cf22eaexe  
2022-10-19 06:01:0457e85409564bed14d33d2ae2663b2bc64f99588c83b208f9091eceaf87097c1bexePlagueBot
2022-10-19 06:00:100ef4667fb2bd5b2184048913181bd7b03bf63d0e7959214b879efa4d6b75ad5dexeQuasarRAT
2022-10-19 06:00:091db78fcbcf1fb8b55618e1e3831c1d4eb4eb4c52a0152da4a7fbf098672a560aexe  
2022-10-19 06:00:087038d241abf9de2da5d859e8565adeaa10f9f3361f9ebc49304f74753b3c31d9msi  
2022-10-19 06:00:07cd9465aa03a8ec2e043575de8cb62be6a55b6cff2d1cd3fea8e1fbcb08cd3816exe  
2022-10-19 06:00:060e5998ca256d11b44071d7d0bc9396e9eaee2bd88c412cbe65481649a1d91a6dexe  
2022-10-19 06:00:069a7f5a09814e2759ea89731a9075d52a1541d124941de8ea9fc6610ff959c387exe  
2022-10-19 06:00:050338fb36fe270413770b9a27017349385bfade88436f3bdbe7771901a8553a6aexe  
2022-10-19 06:00:05cc7dc07df5e85f948998b1d711b7ea362e529799b2f47d35f256ccd901ab3af9exe  
2022-10-19 06:00:05dfb45b729f3d57bfb77d45bcdb32a32bb538fd6e32af5561f51848256688651eexe  
2022-10-19 06:00:0442bc2be4c9351ce730699565086109fd2093e80fe8177197247c2dff3360f101exe  
2022-10-19 05:59:094a6b790629a17abb31de40da6a9faafdedbbc794f3e23816776621a83b068056exe  
2022-10-19 05:59:0781cb1fa3507209f360261e795cc68622c4163cbb0c6082dc7d8358a04492f961exePlagueBot
2022-10-19 05:59:061780430ff5ad71b8c89b9c59d2924b16cb7fd07da479b8b394846c792f7523cbexeOrcusRAT
2022-10-19 05:59:05536be654e06c9e81282d106ecd7aab29ad273fdbd7bdc62a2acfe919060614d2txt  
2022-10-19 05:59:053424b424210b107cfa5570e46913b952e7df8eeaeb099fc55f25bd496f2ff137txt  
2022-10-19 05:59:05faca607d5b505b97923a02c6a7b92517aaa6523d611126609663b0deaf23a315exe  
2022-10-19 05:59:052ad50133104bbae5d82e85737296e39eecbfec15c270afd2a3b6aa981d53215fexe  
2022-10-19 05:59:05934ccdfcadc94fa6a1fc360df1e647a0720aa359ca14c499d87d503b32f12955exe  
2022-10-19 05:59:05934ccdfcadc94fa6a1fc360df1e647a0720aa359ca14c499d87d503b32f12955exe  
2022-10-19 05:59:0533a89ee8019d7a059a32f3fbb645a8d3db31610ea72e581f63dbb3b3cc805dc7exe  
2022-10-19 05:59:05fecc01cea1525c7abdec72afc8a4297c85fea77a87e9fd7f8d15d67718dd50b9exe  
2022-10-19 05:59:05e68d0cd3c71cbdc381b7ab303c23ea64769579723a7e916ca3bbb28b5bf06f15doc 
2022-10-19 05:59:05e0a4c6178a5b6a698a1fbb26e153e186da8e120a5ea795b7c33670609538522czip  
2022-10-19 05:59:0407bb4a9d4d29a7cf09d69102238fc78255c5bc2a01fdc9ac6e7ac39e9c48ed75txt  
2022-10-19 05:59:0453aef6261df3f802393d9196a5c87e69d1e07e2aaff45a606344b91f5801255aexe