URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 159.75.172.32
Firstseen:2026-01-11 07:38:04 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-11 07:38:05 159.75.172.32Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-11 07:38:08http://159.75.172.32/Server/third-party/winvnc....Offlinehuntio opendir ua-wget BlinkzSec
2026-01-11 07:38:08http://159.75.172.32/Server/third-party/winvnc....Offlinehuntio opendir ua-wget BlinkzSec
2026-01-11 07:38:05http://159.75.172.32/cobaltstrike4.9.1_mod/payl...Offlinehuntio opendir ua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-11 07:38:08c50183eed715ec2392249e334940acf66315797a740a8fe782934352fed144c6dll  
2026-01-11 07:38:0813feaa32e4b03ede8799e5bee6f8d54c3af715a6488ad32f6287d8f504c7078bdll  
2026-01-11 07:38:05e79d3062e1d9c813d30152a7af6a49040408d939d88b191510ee20533d61db8aunknown