URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 158.94.211.222
Firstseen:2026-03-06 11:40:06 UTC
Total malware sites :35
Online malware sites :18 (51%)
Offline Malware sites :17 (49%)
Newest active malware site :2026-03-07 08:32:07 UTC
Oldest active malware site :2026-03-06 11:40:08 UTC (Age: 22 hours, 39 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-06 11:40:08 158.94.211.222SBL686264AS202412 OMEGATECH-AS- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-07 08:32:07http://158.94.211.222/files/8468794285/iBC1OE9.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-07 07:06:05http://158.94.211.222/files/unique2/random.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-07 05:20:10http://158.94.211.222/files/8548282130/trP9KGI.exeOnlinedropped-by-amadey fbf543 QuasarRAT ext Bitsight
2026-03-07 05:08:12http://158.94.211.222/files/8548282130/trP9KGI.batOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-07 02:53:09http://158.94.211.222/files/8468794285/5vroDFE.exeOnlinec2-monitor-auto dropped-by-amadey OffLoader c2hunter
2026-03-07 00:05:10http://158.94.211.222/files/6902778688/uxQfUNw.exeOfflinedropped-by-amadey fbf543 VenomStealer Bitsight
2026-03-06 21:35:09http://158.94.211.222/files/1797567872/w6UBu3m.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 21:06:09http://158.94.211.222/files/8733674968/jLZuxmu.exeOfflinec2-monitor-auto DarkVisionRAT dropped-by-amadey c2hunter
2026-03-06 17:11:07http://158.94.211.222/files/2070717540/IPvJTgG.batOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 16:17:06http://158.94.211.222/files/7044575709/ABbqsJz.exeOnlinedropped-by-amadey fbf543 SalatStealer Bitsight
2026-03-06 15:33:09http://158.94.211.222/files/1225117411/Blr3MBe.msiOfflinec2-monitor-auto connectwise dropped-by-amadey c2hunter
2026-03-06 15:00:11http://158.94.211.222/files/7362035837/T3f3JTM.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 14:56:09http://158.94.211.222/files/6902778688/bQVtGjS.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 14:47:10http://158.94.211.222/files/5758620506/HjZucsF.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 14:34:08http://158.94.211.222/files/6149304756/t1nM7M0.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 13:37:07http://158.94.211.222/files/7309295924/SpdWqa6.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 12:58:09http://158.94.211.222/files/8468794285/sBC01fa.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 12:52:09http://158.94.211.222/final/random.exeOnlinedropped-by-amadey fbf543 NirCmd Bitsight
2026-03-06 12:29:07http://158.94.211.222/files/1660459253/W3Trdgs.exeOfflinedropped-by-amadey fbf543 Bitsight
2026-03-06 12:15:10http://158.94.211.222/files/6961337700/4p8oGAO.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 12:10:08http://158.94.211.222/files/6608710704/1r6sQRc.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:10:08http://158.94.211.222/files/gop/random.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:09:13http://158.94.211.222/files/7725193537/jdVAN80.exeOnlinec2-monitor-auto dropped-by-amadey rustystealer c2hunter
2026-03-06 12:09:11http://158.94.211.222/files/5908119101/gkmdY2O.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 12:09:08http://158.94.211.222/files/7260582679/YOaxz85.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 12:09:08http://158.94.211.222/files/8243287745/p9ulf8e.msiOnlinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 12:07:08http://158.94.211.222/files/7782139129/PKenO2z.exeOnlinec2-monitor-auto dropped-by-amadey SalatStealer c2hunter
2026-03-06 12:07:07http://158.94.211.222/files/8499672124/b1JNsvy.exeOnlinec2-monitor-auto dropped-by-amadey Fuery c2hunter
2026-03-06 12:07:07http://158.94.211.222/files/5900855435/eNLe4nm.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:06:07http://158.94.211.222/files/7453936223/5GFpJxh.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:06:07http://158.94.211.222/test/random.exeOnlinedropped-by-amadey fbf543 Bitsight
2026-03-06 12:05:10http://158.94.211.222/files/7290860719/OTcX1Qs.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:05:09http://158.94.211.222/files/7411337060/ZCGm9Ky.exeOnlinec2-monitor-auto dropped-by-amadey Vidar ext c2hunter
2026-03-06 12:01:07http://158.94.211.222/files/6149304756/9MVYpgf.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2026-03-06 11:40:08http://158.94.211.222/vidar/random.exeOnlineAmadey c2-monitor-auto connectwise dropped-by-amadey c2hunter

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-07 09:19:14d32a7418dbab5c43ca9be893ccdf4b7edae9276dc8bb53bbb759b78d65d32437exe  
2026-03-07 08:32:07317f523b62941f1a5426963055fd27a7660a8273d0bf22a77fece8800230980cexe 
2026-03-07 07:49:41d51df332558a7bd2908e81b2896d5dbdc100b33e849546dacdf54296ae4332e5exe 
2026-03-07 05:20:09b9b51e29d004739a401a3628bd5b48cccb9bfa5bbc67dbacd3be197a5be32285exeQuasarRAT
2026-03-07 05:08:128ff80af7d51289e13443a22df16d96b6c5e6354246c5d1f3074a5e689d81dbdabat 
2026-03-07 03:27:01973f2013840e54bd9b12e31938b0592cad17c23425304fecd1ce072aad4d45d2exe  
2026-03-07 02:53:15cd139883e7c08001becf7a9a864c91691bc243c3adb5c87ce94729f9b24a56ceexeVenomStealer
2026-03-07 02:53:0948a48aa818438aa9ac6086b788126309ae61094539623d62b6298f3372e222bbexeOffLoader
2026-03-07 00:05:10e90b8cbcfba56c57f910b0937fc27c5b9719c409ea225df575499174235e302bexe 
2026-03-06 21:35:09b7baebce1e80a690c32b9da7891c455f27deae7ccf33a4353226b2ccf97ee77aexe 
2026-03-06 21:06:096700075bf252fbc09453df6f543d36bbd7f7a011ed2b5bf7fc86df1c4b634c8dexeDarkVisionRAT
2026-03-06 20:59:04cb1da42e8e4283d5639f54e319dcd76480d9a507206e5b328aa8a6795c6404c3exe  
2026-03-06 19:48:04302e42beb59e7f9e5695e97fc188cdbef735cdee5f3c44f080e5e52d6e2df995exe ConnectWise
2026-03-06 17:11:0705d6f4e462065f3c5c3710775f15f96d333ff3d35ea7860536c6208ff4c2f294bat 
2026-03-06 16:17:069c03d2476f5d46c9a49eb40c5a744ebba7ca8d4036924e426e652627568f87d0exeSalatStealer
2026-03-06 15:33:094d24949840cbe6127c1a949786a10fd526693cb8ae286be0da8fcd776f635387msiConnectWise
2026-03-06 15:20:32083ec9b49d1fda4e4485781203013d8552a71eb8f2b464acaab9cbd97b4ac3d6exe 
2026-03-06 15:20:1194bd0cc1f5b87d454af3f6be2ea6f6531795fb6b6d1078136f6701121715c25fexe  
2026-03-06 15:00:109a8ee12f874e254932ba9c6c3ba726e5b083409e9874efd21c6534c5f40a624aexe 
2026-03-06 14:56:097c0d1a9f2480add073c0ec9d8ee3de476e226a87bf92106c256dcc8fdd94cf4eexe 
2026-03-06 14:47:102abf9d6ed195f9d061f4948972e0bdb67741b5d19f9ab60eb55dadd79c529698exe 
2026-03-06 14:34:08083ec9b49d1fda4e4485781203013d8552a71eb8f2b464acaab9cbd97b4ac3d6exe 
2026-03-06 14:27:5131f7ed8a31c353eedc8fc2e6d3b3c1595cc6b586d97b0d3d4692e0807e52d6f3exe 
2026-03-06 14:17:27bd4c96efb1ffcd39501d6fd1a32922efca5030161df6107f5fac39598397ec5aexe 
2026-03-06 13:37:07744e8a3df80d94db5aaec3b7bdf630d680068dab28d65c07386bc82b44078bb9exe 
2026-03-06 12:58:09b12b1bd3046f0e1b4838f187c334633b63df4cc76934ddf6140d9f3c008f5339exe 
2026-03-06 12:52:090d6f9701bbe0142a18e081bdd354895d9e3d678bbacd0a84c4080ea3eaeed5ebexeNirCmd
2026-03-06 12:29:07730e9e0bd0a41438d7d7af227f1441b4f9d8a54988e0add3a2e0fbd7312cc163exe 
2026-03-06 12:15:10303a09eb23736481748f307d4945bc332a76f45a2fa5fc137fcfdc009b4cc289exe 
2026-03-06 12:10:08209b9780a3ee377f4c3b9174522a906f2e487d479041dddbec5eaed627c2e3d2exeVidar
2026-03-06 12:10:080b672807d7526c571d3809112ca0d04e3df926b5414d00cb8a6d73f59a172e9bexe Vidar
2026-03-06 12:09:1320dc254b66b8616088c5122b29211d7102306484b550f75caee7ec9b2a02e71fexeRustyStealer
2026-03-06 12:09:117c519ab5b4da70d36c04ed39744f99ceb52d877c107c45cf7f731518fcb2c2d2exe 
2026-03-06 12:09:08e06dbe87f6cdcfc942f274c4d7883a5ebadf48b7d5eab2a9ef0e900783a8e915msi 
2026-03-06 12:09:08b80ac13edccd2ca442221d7b22a6e8c7eb98688426582d38bf4ebbd5e0ab265bexe 
2026-03-06 12:07:0830a50cc0f7b317c9734e6792e7e4ec174035d92031bdcc87a80ad8826adc60b2exeSalatStealer
2026-03-06 12:07:0718e9a8bfad425d3ff9c0ab3d71e6890320166127b8bdf7460a7edd30f45be0abexeFuery
2026-03-06 12:07:075ac53e312732078514a827b41e1b2cbc6e7161970f9d9ad91f382eede969ac39exe Vidar
2026-03-06 12:06:0750c063208801f6250ad0984212bbff667fa4b979b5443a639b24bc5bbdce0b5dexe  
2026-03-06 12:06:07928b819cbc327ba9d52090b4961d6194e5d3683152ea9ce947d734c5497bec52exe Vidar
2026-03-06 12:05:10299f253ef5a0f06b347cdfeab309c849cf7951a227ed4c13efb61ddf48c1c8e5exeVidar
2026-03-06 12:05:0969c7b3654300bd7f94ba603da9be8f743442dc2e07504685a07f79f1cc318b4cexe Vidar
2026-03-06 12:01:071c63dd5c645b215c7dc0e0e4ef509e9394da2669564f79eb4caae43ad59fe0d6exe 
2026-03-06 11:40:07ab4a92b1b4fd0320e7a13519c8c2b8fa8a828ec56db52864dd70dc48061604b3exe Amadey