URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 15.164.219.57 |
|---|---|
| Firstseen: | 2021-11-17 11:35:03 UTC |
| Total malware sites : | 7 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 7 (100%) |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2021-11-17 11:35:04 | 15.164.219.57 | ec2-15-164-219-57.ap-northeast-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | KR | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-11-18 01:02:06 | http://15.164.219.57/mal/test_1.exe | Offline | 32 exe njRAT | |
| 2021-11-17 14:12:05 | http://15.164.219.57/mal/test_15.msi | Offline | MetaMorfo | |
| 2021-11-17 14:07:05 | http://15.164.219.57/mal/SHIPPMENT.exe | Offline | 32 AgentTesla | |
| 2021-11-17 11:35:06 | http://15.164.219.57/mal/test_16.exe | Offline | RedLineStealer | Anonymous |
| 2021-11-17 11:35:05 | http://15.164.219.57/mal/test_3.docm | Offline | emotet | Anonymous |
| 2021-11-17 11:35:05 | http://15.164.219.57/mal/test_11.vbs | Offline | Anonymous | |
| 2021-11-17 11:35:04 | http://15.164.219.57/mal/test_5.ppam | Offline | AgentTesla | Anonymous |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-11-18 04:29:49 | 10aaca05e9ba57cbec08ea4fac64500f3774c9e6be1df10e86f4d007e5bba9e5 | docx | ||
| 2021-11-18 01:02:06 | 2c6fae2182c59ef4cee6b63e29cf7fa66990e40ad5c22b6a469d3c935766202c | exe | njrat | |
| 2021-11-17 14:12:05 | f67a12cfac8cc2bd55220006aaef6f26bcb1d46dd5229344c9e56bf547755f5f | msi | Metamorfo | |
| 2021-11-17 14:07:05 | 2ce59667fd45c61f031085058709cb4532af062827c15044d2fa340e6a465c23 | exe | AgentTesla | |
| 2021-11-17 11:35:06 | fa9e3e8282175677e1bf926361df6aa60510a6ba8d3d8857d9c9cd850d971d60 | exe | RedLineStealer | |
| 2021-11-17 11:35:05 | 8bb3f60cb3c43b4a4e448df77b04e860279b2f097d6952d6a7105b4a9a7b0970 | docx | Heodo | |
| 2021-11-17 11:35:04 | 48c521a27ae26f20788c0ebcc8387ad7995e9ecc131ea0779870736fed704668 | unknown | AgentTesla |
KR