URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.198.50.76
Firstseen:2026-06-11 07:49:04 UTC
Total malware sites :4
Online malware sites :4 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-06-11 07:50:10 UTC
Oldest active malware site :2026-06-11 07:49:07 UTC (Age: 1 day, 19 hours, 15 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-06-11 07:49:07 154.198.50.76Not listedAS138995 ANTBOX1-AS-AP- SCyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-06-11 07:50:10http://154.198.50.76:8080/1.d00Online abuse_ch
2026-06-11 07:49:08http://154.198.50.76:8080/dusbng.resOnline abuse_ch
2026-06-11 07:49:07http://154.198.50.76:8080/1.1x1Online abuse_ch
2026-06-11 07:49:07http://154.198.50.76:8080/dlters.xmOnline abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-06-11 07:50:09071dc6630c4dfcda06113444db326d6175d9260ac45d5b7186b790237342174bdll 
2026-06-11 07:49:083f738705c0c1e771419fc3b6304cae29aaaaaf63ba63860eb3f68f103f2a5d23unknown  
2026-06-11 07:49:072025f9efd6e3166d7b69dd166a472f7fde21bc92dbef39c1f0e324ecd5088ea1exe  
2026-06-11 07:49:07d4b200539513c03f1b044ba93b93d0cb3fcc0c934a10470fd0b39ed32c50deffunknown