URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 161.129.44.62
Firstseen:2022-10-25 05:23:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-25 05:23:05 161.129.44.62Not listedAS213122 HYONIX- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-27 08:34:06http://161.129.44.62/80/vbc.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-10-25 05:23:05http://161.129.44.62/78/vbc.exeOfflineexe Loki ext jstrosch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-27 08:34:069ea9e37ac1dbdbf112de65d1aea38f6c30977e7af3b1f460d5c1530332d371fdexeAgentTesla
2022-10-25 05:23:0457e9ce8a8b2ed57e367fe58657005e73fd3bd1d13ad7de0a70b9bd46656737f8exeLoki