🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.125.50.8
Firstseen:2025-03-08 04:47:02 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-08 04:47:05 185.125.50.8111870.h2.nexusNot listedAS215730 H2NEXUS-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-11 07:13:06http://185.125.50.8/mVsXkjvb3/Plugins/firefox.exeOfflineCoinMiner JAMESWT_MHT
2025-03-11 07:13:04http://185.125.50.8/mVsXkjvb3/index.phpOffline JAMESWT_MHT
2025-03-08 04:47:05http://185.125.50.8/mVsXkjvb3/Plugins/clip64.dllOfflineAmadey dll abuse_ch
2025-03-08 04:47:05http://185.125.50.8/mVsXkjvb3/Plugins/cred64.dllOfflineAmadey dll abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-14 23:50:4248417475048097cf10085d66db9021a4f6d5d60166a48ab24e009913898f04c3dll  
2025-03-11 07:13:067df393c65a25d134df844c8d18c94f678e234a4a6b45776b9ed4dea6f3416089exeCoinMiner
2025-03-08 04:47:057817b60d8a52034bdfcaf9c0f08f52a86218e4cc44ffd2cb763d90aea26ea227dllAmadey
2025-03-08 04:47:05080ea1d225c77364abb02fbb1b65e9693654242ecc5c91f34c531ecf363a2f4cdllAmadey