URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.196.222.10
Firstseen:2022-12-26 17:05:05 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-26 17:05:12http://185.196.222.10/doroti.exeOfflineDanaBot ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-26 20:47:00ed0e71d2830dca4a177ca15f4201d3a7ce24e1c895bc1bc1473384798c0626dfexe 
2022-12-26 19:05:5566444da71bdd7570977fc01f714dfebca04b9d0859af9eb178308f9d1fa31f98exeDanaBot
2022-12-26 18:20:368310bdd07ed7c0d8a6dba680454829fba782bcf66042940f8275a0b02ca13415exeDanaBot
2022-12-26 17:05:0650936b41b6d60447697ef0626dfd6c5d03679db241da3e3b76488654a7fcd0f0exe DanaBot