URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.196.10.146
Firstseen:2024-01-14 20:01:05 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-01-14 20:01:07 185.196.10.146SBL640645AS42624 swissnetwork02- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-02-09 06:20:37http://185.196.10.146/sig.exeOfflinedropped-by-SmokeLoader spamhaus
2024-02-09 06:20:37http://185.196.10.146/Aytvquiio.exeOfflinedropped-by-SmokeLoader spamhaus
2024-01-29 07:09:08http://185.196.10.146/Iiympojf.exeOffline64 exe PureLogStealer zbetcheckin
2024-01-29 03:56:06http://185.196.10.146/Vbsveuhnjb.exeOffline32 Amadey exe zbetcheckin
2024-01-28 03:24:08http://185.196.10.146/GTALaunchUpdate2.4.exeOffline32 exe PureLogStealer zbetcheckin
2024-01-28 00:58:06http://185.196.10.146/Imteahzda.exeOffline32 Amadey exe zbetcheckin
2024-01-26 07:52:07http://185.196.10.146/Gzcueoarue.exeOffline64 Amadey exe zbetcheckin
2024-01-26 07:03:06http://185.196.10.146/Cxqdczh.exeOffline64 CoinMiner exe zbetcheckin
2024-01-22 00:47:05http://185.196.10.146/Oscrcelw.exeOffline64 exe zgRAT zbetcheckin
2024-01-21 21:01:08http://185.196.10.146/Zzbifmr.exeOfflineAmadey dropped-by-SmokeLoader Casperinous
2024-01-21 16:08:09http://185.196.10.146/plugin3.dllOffline abuse_ch
2024-01-21 16:08:09http://185.196.10.146/panel/uploads/Ohbvdgabs.vdfOffline abuse_ch
2024-01-21 05:02:08http://185.196.10.146/Aixnslkoum.exeOffline64 CoinMiner exe zbetcheckin
2024-01-19 07:00:11http://185.196.10.146/Ylcqwdizkq.exeOffline64 CoinMiner exe zbetcheckin
2024-01-19 03:52:06http://185.196.10.146/Sjupttbqke.exeOffline64 Amadey exe zbetcheckin
2024-01-18 05:41:06http://185.196.10.146/variousstored.exeOffline32 Amadey exe zbetcheckin
2024-01-18 00:52:07http://185.196.10.146/Zumyefllhkv.exeOffline64 exe PureLogStealer zbetcheckin
2024-01-16 18:47:06http://185.196.10.146/dnjupddater.exeOffline64 exe zgRAT zbetcheckin
2024-01-16 05:22:08http://185.196.10.146/Zxgdah.exeOffline64 CoinMiner exe zbetcheckin
2024-01-15 04:48:05http://185.196.10.146/khupdated.exeOffline32 AsyncRAT ext exe zbetcheckin
2024-01-15 04:48:05http://185.196.10.146/Tufjz.exeOffline64 exe zbetcheckin
2024-01-14 20:01:07http://185.196.10.146/axemupdate.exeOfflineAsyncRAT ext dropped-by-SmokeLoader Casperinous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-29 07:09:08b3e052743e942d601719b413754f2d7539be318e8af20de6c476e175dc1bd000exePureLogStealer
2024-01-29 03:56:0649b524dbe9797e4a8905bca4b74da0f7aac977b07a5f72c66e7f3d22597a86e7exeAmadey
2024-01-28 03:24:08a6c05c63623b019614ab1d5cf533f9599d42fe18773d1d92cb1caccee809d2aeexePureLogStealer
2024-01-28 00:58:062e5cabd0ef1a25258496aa4a32c0a23338f72df7da07b4753eefab0982c81540exeAmadey
2024-01-26 07:52:078afcc55b59e124b3840bbee5afb30e70354590eee693480a43fe7d586e909a9eexeAmadey
2024-01-26 07:03:06258b937ad6b2792590e96e751999299d518afbefc4afb454263de83f2c2a0b5eexeCoinMiner
2024-01-22 00:47:05003552c7c95845ab8bd7638e9c3365607701aff4d82220154debf9f8559171eeexezgRAT
2024-01-21 21:01:08585892aac1dd2104c9dc5badf75efbc0d5f363456c084741af5e251402473de0exeAmadey
2024-01-21 16:08:09d3a8addf4b7103055780badca7ba147b654d6e83b42c2e0edca0589258c9d1abunknown  
2024-01-21 16:08:094f8f521f4d3b888046a1e4731f3f9ba700715ac0db6230195f6116e8a3893f0aunknown  
2024-01-21 05:02:08304a4f68bfff226a2049f6c5b38f915487ac75f5b6b62e74d17114bb05669c49exeCoinMiner
2024-01-19 07:00:11f055dcd0d16bf5d03427b204fc34f6785340c2864b7693b3179214ab303d1d77exeCoinMiner
2024-01-19 03:52:060452dcaafbe9bc6dfee7a44e35738477a4e99a00983593aba7698c4636a5f59cexeAmadey
2024-01-18 16:03:07892058240bc6a2ed5877e406fd7e4e8e8ed7df1c2a89a82f5ffa9f62824730a5exe  
2024-01-18 05:41:0655f6a167e9a16bc90f6009a105bc6484c3969b0ea2c9767ab9b4c0ef78bb6b03exeAmadey
2024-01-18 00:52:07415f5fa648158c6b38db8c701b39159a4b5eef7ec174616fd9204b2ea96a48f4exePureLogStealer
2024-01-16 18:47:0672f5f9230c025a393d1362241679fd0dd5c48b7e3786591f35b3f74eccf53978exezgRAT
2024-01-16 05:22:08d34bb3f51cd2e0628fa294d9459f58156b82ece676aa4ec78b90ad8dc484b210exeCoinMiner
2024-01-15 04:48:05b29156030acc1b80de8d66c918e137a33cd1ee264f9695ec96be208cf5faf10bexeAsyncRAT
2024-01-15 04:48:05a6c97a42e104ca012e600d401a95a1e6044bad4dc97783e066a76483e5104359exe 
2024-01-14 20:01:0768d282c16c83a849e29fb395b3e1864c3df158edf47a92ffb078b81dcafd7888exeAsyncRAT