URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 169.1.16.29
Firstseen:2024-10-17 16:10:07 UTC
Total malware sites :21
Online malware sites :0 (0%)
Offline Malware sites :21 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-10-17 16:10:13 169.1.16.29mail.cybervip.co.zaNot listedAS37611 AFRIHOST-SP- ZAyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-10-17 16:10:26http://169.1.16.29/Swift-Beacon-Encrypted.exeOfflineopendir Sliver abus3reports
2024-10-17 16:10:25http://169.1.16.29/Swift-Stage1-Obfuscated.exeOfflineopendir Sliver abus3reports
2024-10-17 16:10:19http://169.1.16.29/BidvestBank-Swift-evasion-en...Offlineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/index.bakOfflineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/swift-no-obfuscation-x64.binOfflineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/LOUD_EYEOfflineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/S.binOfflineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/BidvestBank-Swift-ssh-evasio...Offlineopendir abus3reports
2024-10-17 16:10:19http://169.1.16.29/swift-nobypass.exeOfflineHavoc opendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/Swift-sleep10-jitter-50-amsi...OfflineHavoc opendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/BidvestBank-Swift--DNS-evasi...Offlineopendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/BidvestBank-Swift-AD686-evas...Offlineopendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/Swift-Sleep-bypass.exeOfflineHavoc opendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/BidvestBank-Swift-Manual-Eva...Offlineopendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/swift-obfuscation-side-loadi...OfflineHavoc opendir abus3reports
2024-10-17 16:10:15http://169.1.16.29/BidvestBank-Swift-DNS-Tunnel...Offlineopendir abus3reports
2024-10-17 16:10:14http://169.1.16.29/Swift-service-encrypted-obus...OfflineHavoc opendir abus3reports
2024-10-17 16:10:14http://169.1.16.29/demon.x641.exeOfflineHavoc opendir abus3reports
2024-10-17 16:10:14http://169.1.16.29/demon.x64.exeOfflineHavoc opendir abus3reports
2024-10-17 16:10:14http://169.1.16.29/swift-bypass-breakpoints.exeOfflineHavoc opendir abus3reports
2024-10-17 16:10:13http://169.1.16.29/index.jvhOfflineopendir abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-10-17 16:10:25cdaf492c993c9e64b6d299496bd57d52ddd362a32cff1dd9576bb07a6950edfeexeSliver
2024-10-17 16:10:25a3ae935dad0de2657b032a70d1908f622b3cf54fc53f01a69d5f086e21ad4d9aexeSliver
2024-10-17 16:10:11e72717c3598893ddb4444f71747b3010171ed14737d63d043ecf9ec7844fd5a5dllHavoc
2024-10-17 16:10:11add0fc7c0ee95037188480e1cf178635c0ca08bef781a8b64b2f2f69dad601b7unknown 
2024-10-17 16:10:11df5618ae279de70e7e507716452ed9974e68413c243c3ef3f6b67f3b6d51bb8aunknown 
2024-10-17 16:10:11c3e4960c08753b4bc483ab8620688f2c9c06d2b55f69c3521cc5643ccfdc70a2unknown 
2024-10-17 16:10:11fc6986a8b877eb38d882e3fe96b6edcd6c357d611b76f4cfc6873e272acc293aunknown 
2024-10-17 16:10:1154f5603c31f360beaf872181bf60e0c65c86b2d1c256408991cf6e3d0f362d32exeHavoc
2024-10-17 16:10:113cedcfd685fc0372bc6624670a3c830201485b2b9944e35d53e182fcfe6dc01eunknown 
2024-10-17 16:10:1112d1b3cfd5b410cc39cd4b74a699c4d31846f551fae776a542f4d26d45c61808exeHavoc
2024-10-17 16:10:115f04f6ec0a23d4c53fed030f87d7bccc034a7cc1fe14ce0c83f3856d0309be72unknown 
2024-10-17 16:10:11c1a79af2db1fd681a749a3c496c0d40b6f493b8cef94baefcfe7d3522eceedeaexeHavoc
2024-10-17 16:10:11f406bfe6bc650c8c967654fd4d73589e4406ed2cafbba3724181d904f1ac30eeunknown 
2024-10-17 16:10:11c0f272047eec9b7ad1e3456ac0ae020c2522022d69ef6576a99000b967d7f5cfdllHavoc
2024-10-17 16:10:11ee5094722b75240eadf7a89add82487769307a1a7e5b8a14fb3ce854d5974e16unknown 
2024-10-17 16:10:11a87ec35ffa4d698eddfe69cea22dccba56afe78fbd34529672d3eedc98b84350exeHavoc
2024-10-17 16:10:11b646ecc8fbd94b4b583cc46ed8443bf2e6596095ff087a5591abf0f9fb1b6fb3exeHavoc
2024-10-17 16:10:11db58a931d38306d3925aba738425200f14fc3e93054f5f3e3fdea3813c23e366exeHavoc
2024-10-17 16:10:10a3317022d4230fd50b88562b7e92c8006a8f78d4f1436f296e0aaac126aed834unknown