URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.201.74.240
Firstseen:2024-04-01 08:00:11 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-04-01 08:00:16 154.201.74.240Not listedAS8796 FD-298-8796- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-05-30 08:00:15http://154.201.74.240:2263/csrss.exeOffline misa11n
2024-04-19 08:00:08http://154.201.74.240:14867/windows.exeOfflineGh0stRAT misa11n
2024-04-05 08:00:12http://154.201.74.240:9854/mstsc.exeOfflineGh0stRAT misa11n
2024-04-01 08:00:16http://154.201.74.240:8765/mstsc.exeOfflineGh0stRAT misa11n

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-05-30 08:00:15c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702cexeZegost
2024-04-19 08:00:0872e63f73ced48b29f196e48030215273a17f7827c310f2747321cbc1f388c206exeGh0stRAT
2024-04-05 08:00:1272e63f73ced48b29f196e48030215273a17f7827c310f2747321cbc1f388c206exeGh0stRAT
2024-04-01 08:00:1672e63f73ced48b29f196e48030215273a17f7827c310f2747321cbc1f388c206exeGh0stRAT