URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.11.61.104
Firstseen:2024-12-16 11:17:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-16 11:17:05 185.11.61.104SBL690074AS57523 changway-as- HKyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-16 11:17:05http://185.11.61.104/Z.pngOfflinedropped-by-Stealc png abus3reports
2024-12-16 11:17:05http://185.11.61.104/A.pngOfflineAmadey dropped-by-Stealc png abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-01-20 18:59:19969c56d51c5e424022b331b799bbf6a632112457e29364aaab557aaaab0b36a4ps1 Amadey
2025-01-16 18:21:079fdddc791c9587308ebde319912a86f94a1172de8a6454ce0019f093fefc7504ps1  
2025-01-16 18:20:5055dcda854a4cc8027ac2095e186643582021d2f903946b18acbdb9833408bf1eps1 Amadey
2025-01-10 20:35:05840dd1e29f8331e60e7eb513a05bad4b4809b0d9c0d463f6a379b4fb5f1fbd09ps1  
2025-01-07 14:57:40d65d87ab0447ebd71d228e52749c97bb1e732b8a2f4c31537b08bff29fc27768ps1Amadey