URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.196.9.161
Firstseen:2023-11-11 09:12:03 UTC
Total malware sites :10
Online malware sites :0 (0%)
Offline Malware sites :10 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-11 09:12:06 185.196.9.161SBL640645AS42624 swissnetwork02- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-26 05:52:06http://185.196.9.161/Mmotwvfgpde.exeOffline64 exe zbetcheckin
2023-11-24 16:32:05http://185.196.9.161/Jqjfw.exeOffline32 Amadey exe zbetcheckin
2023-11-24 06:13:06http://185.196.9.161/Opesi.exeOffline32 exe Vidar ext zbetcheckin
2023-11-24 03:04:06http://185.196.9.161/Wlssejinnvz.exeOffline64 exe zgRAT zbetcheckin
2023-11-20 06:25:10http://185.196.9.161/hvupdater12.exeOffline32 exe zgRAT zbetcheckin
2023-11-18 06:06:06http://185.196.9.161/v1.exeOffline32 exe MarsStealer zbetcheckin
2023-11-17 18:11:07http://185.196.9.161/Chjirossjr.exeOffline64 Amadey CoinMiner exe zbetcheckin
2023-11-16 04:10:20http://185.196.9.161/Aaezheyu.exeOffline64 exe zgRAT zbetcheckin
2023-11-13 07:58:07http://185.196.9.161/Rjiyeslhtb.exeOffline64 exe zgRAT zbetcheckin
2023-11-11 09:12:06http://185.196.9.161/Nfwwamql.exeOffline64 exe zgRAT zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-30 02:07:5120f894c77415be99a1f652a897af6c153de7d5994d3f233e391b1b49559ebffcexe  
2023-11-26 05:52:0615a05098b91575cb0da6964367040dc8a0051a4fa8a0db4d26fdb8aaa570ceaeexe 
2023-11-24 16:32:0593583dfa872b44e13e449cdfbbe20e64851dbe0e615f30b0313d2cb6a9b2309eexeAmadey
2023-11-24 06:13:063c16def99c05de25b1b8dfb73757f3356bad519c9c39292752aa07fab0653936exeVidar
2023-11-24 03:04:0678622732081a2280320cbd61ae9c1cf51061ad534b537cf6010144e41e29bb67exezgRAT
2023-11-21 01:25:04f8e0ece0ff3a16a06fd53e8855b422bf3b2ced48d3facfd954526b1c6b6a42a6exe Amadey
2023-11-20 06:25:10ebb20ee3f9c28aa7e7a1fe1cdc8371c56a17f2f17bf8d98139fea30915e2be0fexezgRAT
2023-11-18 20:15:47d8352d51143cdb130eb1c633fcc91b688df4961fcbe97a286c88112884266833exeMarsStealer
2023-11-18 14:29:319bdcaf14e9f27607ce4c446a38ab2e187e0cd4f1c74176108a39c9eefa10bcb1exe  
2023-11-18 06:06:06129945bc24fc3a0f026201998f746fdaa548460d5822822d305a9f1ab68db413exeMarsStealer
2023-11-17 18:11:073f26b871b1e556d19b67814d3a758316b655cd508be014a2eea2cf40e1371b94exeCoinMiner
2023-11-16 04:10:2037c232d654467909a6f6ddcd25d59d81e0c8bb3b5873c8ee46f87d093bc10e8aexezgRAT
2023-11-13 07:58:07f943cf382d0c97c65b9ab3402d85118ee810127b648eb9fcc07c3f3404b281aeexezgRAT
2023-11-12 05:34:47795e333056f12db05a5c212318e3f1e3d915a8e7f88737fc34321465a6c1bfadexezgRAT
2023-11-11 09:12:06a1765648a41eea21fd942776cba9b50705673d8f7564ae7f8c9751eda9e2e564exezgRAT