URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.112.83.111
Firstseen:2022-07-04 07:19:03 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-07-04 07:19:05 185.112.83.111cagey-oil.aeza.networkNot listedAS211522 HYPERCORELTD- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-04 10:20:11http://185.112.83.111/kasperskiy.exeOffline32 exe Hive zbetcheckin
2022-07-04 10:20:11http://185.112.83.111/555.exeOffline32 exe Hive zbetcheckin
2022-07-04 10:19:10http://185.112.83.111/pon.exeOffline32 exe Hive zbetcheckin
2022-07-04 10:19:07http://185.112.83.111/uangelll.exeOffline32 exe Hive zbetcheckin
2022-07-04 10:04:07http://185.112.83.111/fik.exeOffline32 exe Hive zbetcheckin
2022-07-04 07:19:05http://185.112.83.111/rat.exeOfflineCoinMiner XFilesStealer KdssSupport

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-25 21:14:551cd3fb684255a081f084e0ec1b9857919d477b5febb517f08b150af57113b9f2exe  
2022-07-22 20:10:50a8b0a6ea2b63c3dd9de21df3631640e83af6a061831bdc677d1367e4591ac7e5exe XFilesStealer
2022-07-21 18:20:52d18712c0330ecd7e69e2f5c4a5158abe8dec025ac0855eca4275b8da3a956159exe XFilesStealer
2022-07-18 11:27:00ced6d4db8220cb82a396e31f49ae4e6d6b25b9327f1d4b89ddbca71de71c7a70exe  
2022-07-12 20:46:4038ce628c98b083b2de29baa5f294dd16e90468926f0101d68f2a1f20c79dea25exe  
2022-07-12 20:27:21e8eafef894080e1d7a650a52bc4390b20efb590ff9f06e63cc3336743facc0d2exe  
2022-07-10 20:01:13f1156e18afdec093a4f8da69a5d11910a119cb9d6d8a7448e8a3655b4023975dexe 
2022-07-10 10:06:07899ded1d2f1eead113908ce02a7f8edec3f152ddbd7ea8b4075d2b67155b5f39exe  
2022-07-08 13:46:05e63a348cc524d9eb1bfaefb1d47a65db9d2653c995c27e60fe5ddcbe8d0d1b51exe  
2022-07-04 10:20:11f8d1e3127dc6b74bcc1ff5c5c147c0f3f8870bae098f2455a89b6162cf2d9e0fexeRansomware.Hive
2022-07-04 10:20:11ccf870c70de4cc412a00deb5f93ad56f4a7b6ad38b8574c31b121759b1745502exeRansomware.Hive
2022-07-04 10:19:100077e7d6e90ad972b64e90c343c617482f39505deff44ebff99ff49041252dcbexeRansomware.Hive
2022-07-04 10:19:07f19a795a01ec22eb27174da923ca0721e22baa7f0982059b0e644c76b6154a3fexeRansomware.Hive
2022-07-04 10:04:07be69a27ea4cea45c49e75a0eb57cd503190d08eb97184c492c084a822e29374eexeRansomware.Hive
2022-07-04 07:19:0473b569701300146f7c31f8017d86e64811f0984acc27afd8831414f21d42cf12exeCoinMiner