URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 172.236.108.48
Firstseen:2025-06-16 22:22:04 UTC
Total malware sites :18
Online malware sites :12 (67%)
Offline Malware sites :6 (33%)
Newest active malware site :2025-06-16 22:22:21 UTC
Oldest active malware site :2025-06-16 22:22:10 UTC (Age: 11 months, 15 days, 5 hours, 54 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-16 22:22:09 172.236.108.48172-236-108-48.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-06-16 22:22:25https://172.236.108.48/MALWARE/flame/boot32drv.sysOfflineopendir Riordz
2025-06-16 22:22:22https://172.236.108.48/MALWARE/flame/msglu32.ocxOfflineopendir Riordz
2025-06-16 22:22:21https://172.236.108.48/DANGEROUS/flame/msglu32.ocxOnlineopendir Riordz
2025-06-16 22:22:19https://172.236.108.48/MALWARE/flame/mssecmgr.ocxOfflineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/DANGEROUS/flame/mssecmgr...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/MALWARE/EnergizerTrojan-...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/DANGEROUS/flame/boot32dr...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/MALWARE/flame/nteps32.ocxOfflineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/DANGEROUS/dnsmasq-2.73rc...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/MALWARE/icecast2_2.0.0_V...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/DANGEROUS/flame/advnetcf...Onlineopendir Riordz
2025-06-16 22:22:16https://172.236.108.48/DANGEROUS/EnergizerTroja...Onlineopendir Riordz
2025-06-16 22:22:15https://172.236.108.48/MALWARE/dnsmasq-2.73rc7....Onlineopendir Riordz
2025-06-16 22:22:15https://172.236.108.48/DANGEROUS/flame/nteps32.ocxOnlineopendir Riordz
2025-06-16 22:22:13https://172.236.108.48/DANGEROUS/icecast2_2.0.0...Onlineopendir Riordz
2025-06-16 22:22:12https://172.236.108.48/MALWARE/flame/advnetcfg.ocxOfflineopendir Riordz
2025-06-16 22:22:10https://172.236.108.48/DANGEROUS/flame/ccalc32.sysOnlineopendir Riordz
2025-06-16 22:22:09https://172.236.108.48/MALWARE/flame/ccalc32.sysOfflineopendir Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-16 22:22:25029bcd72dc2ca4b31778cf4ee086038d8bd6c59ed2ed485e247aed56f909f881unknown  
2025-06-16 22:22:22c6776d9ebe91b2d33b3ac36c845528fd7a81b35095beffbd2ea080fe6eab67cfdll  
2025-06-16 22:22:21c6776d9ebe91b2d33b3ac36c845528fd7a81b35095beffbd2ea080fe6eab67cfdll  
2025-06-16 22:22:19295b089792d00870db938f2107772e0b58b23e5e8c6c4465c23affe87e2e67acdll  
2025-06-16 22:22:16295b089792d00870db938f2107772e0b58b23e5e8c6c4465c23affe87e2e67acdll  
2025-06-16 22:22:165bff7e7c33f1bc57896bd0057efa0ce2d2ab22fd9860b63d24b5725ff54a3d40zip  
2025-06-16 22:22:16029bcd72dc2ca4b31778cf4ee086038d8bd6c59ed2ed485e247aed56f909f881unknown  
2025-06-16 22:22:167d5ad688d1cdb34f8ee694e60b9d47e894c879f23218c5c29a19a514030e706ddll  
2025-06-16 22:22:165e30162f29c972713ffc8b31c2943eb1ef5fb12021bf5847528ee4f1723dbdb7unknown  
2025-06-16 22:22:16e0001c5f08b60a605e607346a0ef512d1444fb4e476f5fb8ab56db4feb12320aexe  
2025-06-16 22:22:1669beb78c8b8de1a86677e27c531c92cb5ca70807d2755b94f70a75887fbc90cfdll  
2025-06-16 22:22:165bff7e7c33f1bc57896bd0057efa0ce2d2ab22fd9860b63d24b5725ff54a3d40zip  
2025-06-16 22:22:155e30162f29c972713ffc8b31c2943eb1ef5fb12021bf5847528ee4f1723dbdb7unknown  
2025-06-16 22:22:147d5ad688d1cdb34f8ee694e60b9d47e894c879f23218c5c29a19a514030e706ddll  
2025-06-16 22:22:12e0001c5f08b60a605e607346a0ef512d1444fb4e476f5fb8ab56db4feb12320aexe  
2025-06-16 22:22:1269beb78c8b8de1a86677e27c531c92cb5ca70807d2755b94f70a75887fbc90cfdll  
2025-06-16 22:22:091999c26614de76068d9431b8184e933c63b5813b76a95fac6cc4b47e93832c23unknown  
2025-06-16 22:22:081999c26614de76068d9431b8184e933c63b5813b76a95fac6cc4b47e93832c23unknown