URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.215.113.38
Firstseen:2021-05-29 03:44:03 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-04 12:05:41http://185.215.113.38/68b591d6548ec281/softokn3...OfflineStealc abus3reports
2024-12-04 12:05:38http://185.215.113.38/68b591d6548ec281/msvcp140...OfflineStealc abus3reports
2024-12-04 12:05:38http://185.215.113.38/68b591d6548ec281/freebl3.dllOfflineStealc abus3reports
2024-12-04 12:05:37http://185.215.113.38/68b591d6548ec281/vcruntim...OfflineStealc abus3reports
2024-12-04 12:05:35http://185.215.113.38/68b591d6548ec281/nss3.dllOfflineStealc abus3reports
2024-12-04 12:05:24http://185.215.113.38/68b591d6548ec281/sqlite3.dllOfflineStealc abus3reports
2024-12-04 12:05:22http://185.215.113.38/68b591d6548ec281/mozglue.dllOfflineStealc abus3reports
2024-11-03 10:02:05http://185.215.113.38/746f34465cf17784/vcruntim...OfflineStealc abus3reports
2024-11-03 10:01:09http://185.215.113.38/746f34465cf17784/nss3.dllOfflineStealc abus3reports
2024-11-03 10:01:08http://185.215.113.38/746f34465cf17784/mozglue.dllOfflineStealc abus3reports
2024-11-03 10:01:08http://185.215.113.38/746f34465cf17784/freebl3.dllOfflineStealc abus3reports
2024-11-03 10:01:08http://185.215.113.38/746f34465cf17784/sqlite3.dllOfflineStealc abus3reports
2024-11-03 10:01:08http://185.215.113.38/746f34465cf17784/softokn3...OfflineStealc abus3reports
2024-11-03 10:01:08http://185.215.113.38/746f34465cf17784/msvcp140...OfflineStealc abus3reports
2022-05-25 07:39:04http://185.215.113.38/f8dfksdj3/Plugins/cred.dllOfflineAmadey dll abuse_ch
2021-05-30 02:51:07http://185.215.113.38/ao.exeOfflineAmadey exe zbetcheckin
2021-05-29 04:32:04http://185.215.113.38/fT5YhO/plugins/scr.dllOfflineexe zbetcheckin
2021-05-29 03:44:04http://185.215.113.38/fT5YhO/plugins/cred.dllOfflineAmadey exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-12-04 12:05:4074ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5adll  
2024-12-04 12:05:385136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062dll  
2024-12-04 12:05:37edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fadll  
2024-12-04 12:05:368934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825dll  
2024-12-04 12:05:33ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5dll  
2024-12-04 12:05:244841020c8bd06b08fde6e44cbe2e2ab33439e1c8368e936ec5b00dc0584f7260dll 
2024-12-04 12:05:21ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196adll  
2024-11-03 10:02:058934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825dll  
2024-11-03 10:01:09ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5dll  
2024-11-03 10:01:08ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196adll  
2024-11-03 10:01:08edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fadll  
2024-11-03 10:01:084841020c8bd06b08fde6e44cbe2e2ab33439e1c8368e936ec5b00dc0584f7260dll 
2024-11-03 10:01:0874ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5adll  
2024-11-03 10:01:085136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062dll  
2022-05-25 07:39:045342a90e6dd43fb471d9674de99d8cdc048381efff246af9de32f9257cacdcc3dllAmadey
2021-05-30 02:51:0787178907c9c47a383a2a08a30481dbc5345b6c85c48142a855900d9840e6b6daexeAmadey
2021-05-29 04:32:0461b0bd1ab9b0a73d137969f4e4c85f8eacd33fb7c19a6ee49cc91817459c4fd4dll  
2021-05-29 03:44:03b232ce459cc455b83776f73ec9d933fd03fd6797f59ea2b36190ceb1d559637fdll Amadey