URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.82.84.114
Firstseen:2025-02-28 21:48:02 UTC
Total malware sites :19
Online malware sites :1 (5%)
Offline Malware sites :18 (95%)
Newest active malware site :2025-02-28 21:48:07 UTC
Oldest active malware site :2025-02-28 21:48:07 UTC (Age: 10 months, 2 days, 1 hours, 2 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-02-28 21:48:05 154.82.84.114Not listedAS399077 TERAEXCH- HKyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-02-28 21:57:06http://154.82.84.114:6635/BugRpt.dll.datOfflineshellcode NDA0E
2025-02-28 21:56:14http://154.82.84.114:6635/38.91.115.206.dllOfflinedll dllHijack Gh0stRAT NDA0E
2025-02-28 21:56:12http://154.82.84.114:6635/27.124.3.252.dllOfflinedll dllHijack Gh0stRAT NDA0E
2025-02-28 21:56:12http://154.82.84.114:6635/27.124.47.29.dllOfflinedll dllHijack Gh0stRAT NDA0E
2025-02-28 21:56:10http://154.82.84.114:6635/38.46.10.90.dllOfflinedll dllHijack Gh0stRAT NDA0E
2025-02-28 21:56:06http://154.82.84.114:6635/BugRpt.dllOfflinedll dllHijack shellcoderunner NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/27.124.3.248.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/27.124.47.29.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/23.248.217.196.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/103.215.212.130_86.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/23.226.57.23.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/23.248.217.134.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/38.91.115.202.binOfflineshellcode NDA0E
2025-02-28 21:56:04http://154.82.84.114:6635/154.207.55.3_86.binOfflineshellcode NDA0E
2025-02-28 21:56:03http://154.82.84.114:6635/38.91.115.42_86.binOfflineshellcode NDA0E
2025-02-28 21:56:03http://154.82.84.114:6635/103.199.100.37.binOfflineshellcode NDA0E
2025-02-28 21:48:08http://154.82.84.114:6635/qqx52_gameBase.dllOfflinedll dllHijack NDA0E
2025-02-28 21:48:05http://154.82.84.114:6635/27.124.42.200_86.binOfflineshellcode NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-02-28 21:57:06755357a50464e175ffb896c9775bf1280a642b18a008c9e8abb1e3e57ee79330unknown  
2025-02-28 21:56:1469ada5ba27acac423073b251d25fc23b09e4d5127f879d07a0c4ae01366ce8a5dllGh0stRAT
2025-02-28 21:56:12e8e0b570da7fe439146d5ab370ae477b391f0ec38ef5bdf42d669bf68c341573dllGh0stRAT
2025-02-28 21:56:12e8e0b570da7fe439146d5ab370ae477b391f0ec38ef5bdf42d669bf68c341573dllGh0stRAT
2025-02-28 21:56:1022344872fa8b5030296a9d5f9fe652c7c6af2db78c43b41ceb9ade73726905b0dllGh0stRAT
2025-02-28 21:56:065d87a7313a9991f65d629e9667b8d4c2b2cd16212dfd13c15fcabf64b1b6f582dll 
2025-02-28 21:56:0418a6b379f526d3b361e9096234d62a9ae7fa046e3f4b250fc1a4d320654d36a6unknown  
2025-02-28 21:56:04cd1164cf3988df22709680d31e59a6f0982b8f4b7cb1e929d39452ba7c01e2cbunknown  
2025-02-28 21:56:040c936bbb0fd3534d9a1507b0180e6a7e10bab488834e28c6e50ef0ff0eabfc24unknown  
2025-02-28 21:56:04b9f182868e9a7295a23db4bc4bb644ca0ac4e873b15cacffbca1c545a1b0957dunknown  
2025-02-28 21:56:04f55ff4faa547437d69a3a8c3ea01dbf5fee98c1a800f09fbecc1e54dced738c7unknown  
2025-02-28 21:56:0441811f648f29e5a3b7fc159419354f110a3775446fe9da07458885fd89b8647funknown  
2025-02-28 21:56:04195ab43f787dcf7eb343ee63dc47b7a8ab55a711cce3ccb6f785c02de8f87ccfunknown  
2025-02-28 21:56:034e728b42f4263b43f0e313a9dad78038906fdda183eae2aef696c434f76ff42dunknown  
2025-02-28 21:56:03639356a4aa1c52287ef7e0100983e19a4b9cb4c45686ccd2dacb1e0483e0eff8unknown  
2025-02-28 21:56:0392c9016cf97663387fa6e60a0d68a2e21ef6717ab4f7fb1859cc1974c41b3f2eunknown  
2025-02-28 21:48:08c36e32994befe6eb41973c8d16959ab2f12832b8db99e278f7aa8cbae087bd52dll 
2025-02-28 21:48:076397988f8f46b82fd519b0a6bfdfeb35966158304369c5608a92adb75ef700fcexe 
2025-02-28 21:48:052e791fffd8abc182b821f1741c8764dc8c918f67d3d9a25f83456e3f611b3c18unknown