URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 18.159.111.216
Firstseen:2021-10-10 07:08:02 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-10-10 07:08:04 18.159.111.216ec2-18-159-111-216.eu-central-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-10-10 07:09:04http://18.159.111.216/www1/lis-0.exeOfflineexe Formbook ext opendir abuse_ch
2021-10-10 07:09:04http://18.159.111.216/www1/lis-01.exeOfflineexe Formbook ext opendir abuse_ch
2021-10-10 07:08:04http://18.159.111.216/www1/lis.exeOfflineexe Formbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-10 07:09:04f0537b93c3ac221e4efe9d5835845b4930529890472272b0b0f8db2bf1d4ca5bexeFormbook
2021-10-10 07:09:045a573da6707c9373b0f49b049b07ddc21bc6976195b834473d0be2daaf52c173exeFormbook
2021-10-10 07:08:04862d9ecd31b3ad9fbdaf4f5c25e2bf5e4abbbb0a922e097a0c0dd69c8acb6ae3exeFormbook