URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 18.140.72.12
Firstseen:2021-04-15 13:09:03 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-04-15 13:09:06 18.140.72.12ec2-18-140-72-12.ap-southeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-04-16 05:38:07http://18.140.72.12/wind/orr7-02.exeOfflineAgentTesla ext exe zbetcheckin
2021-04-16 04:49:07http://18.140.72.12/wind/orr7-03.exeOfflineAgentTesla ext exe zbetcheckin
2021-04-16 04:49:06http://18.140.72.12/wind/xxxx9-02.exeOfflineexe Formbook ext zbetcheckin
2021-04-15 13:10:08http://18.140.72.12/wind/xxxx9-10.exeOfflineexe Formbook ext opendir abuse_ch
2021-04-15 13:10:08http://18.140.72.12/wind/orr7-09.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-04-15 13:10:08http://18.140.72.12/wind/orr7-10.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-04-15 13:10:06http://18.140.72.12/wind/xxxx9-09.exeOfflineexe Formbook ext opendir abuse_ch
2021-04-15 13:09:13http://18.140.72.12/wind/orr7.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-04-15 13:09:06http://18.140.72.12/wind/xxxx9.exeOfflineexe Formbook ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-16 14:48:1910dd6636705588394e6b2610eca43325c8a17d3fc303ba605c1d40bab3a75a13exeAgentTesla
2021-04-16 12:11:37696007cc5cdcc234a7378e44aed248a918143e197901cf1074d6dc07e452ab8aexeFormbook
2021-04-16 07:22:15c39de4a10c23c2b7e7509158e90d38fe6b7d8544b678c3326876829b51bb6b13exeAgentTesla
2021-04-16 05:38:0792301e389bb037a484b2bd9973642c3c9a7415104c33009b17fbd816590db8f2exeAgentTesla
2021-04-16 04:49:071e21738e68114a74266054b4ce1c8489b3f6a373b15cada9e0e08d30cd9d3da6exeAgentTesla
2021-04-16 04:49:065b7770f02c562dffdbe0cd638e288adba8f340c7231ef30fa2860b7f4b9dfa80exeFormbook
2021-04-16 01:10:183d15e2909a2cbedba57a1718b220b187465396969ebaf8f9021847c0b953153cexeFormbook
2021-04-15 16:09:5592301e389bb037a484b2bd9973642c3c9a7415104c33009b17fbd816590db8f2exeAgentTesla
2021-04-15 15:54:235b7770f02c562dffdbe0cd638e288adba8f340c7231ef30fa2860b7f4b9dfa80exeFormbook
2021-04-15 13:10:08c973881d3539e89059c7713b4e24e330f88abee7da38f256034bc25bb4b9e674exeAgentTesla
2021-04-15 13:10:08aa9b97249254e492bda4508cc661f462ed749c6d810d2c915136848189addc38exeAgentTesla
2021-04-15 13:10:0715944a88ca237bb17dde16f5ef5a0dc4122576d8dc80f2d28f2b9555464c05bcexeFormbook
2021-04-15 13:10:06ce99378f7bcd95a0441b3572fe948daeb420ec960719761b249b817e5c0cec37exeFormbook
2021-04-15 13:09:137582182ef873a01a095cdca3e94d8c46c2e86aae1e198960cedceaf9ab7de3ffexeAgentTesla
2021-04-15 13:09:06c9afe6904407e9b60e73edf93efbd932b6725f0f4f33306117ffc9854c21cae2exeFormbook