URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.242.104.78
Firstseen:2020-03-27 07:42:10 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-03-27 07:42:12 185.242.104.78Not listedAS42532 VEESP-LV-AS- LVyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-03 13:13:16http://185.242.104.78/fuwa/Remtc_encrypted_63B4...Offlineencrypted GuLoader ext abuse_ch
2020-03-27 16:48:11http://185.242.104.78/wftp/hamkyyu_encrypted_18...Offline JayTHL
2020-03-27 16:48:08http://185.242.104.78/wftp/kayslimmmm_encrypted...Offline JayTHL
2020-03-27 16:48:05http://185.242.104.78/wftp/out-571924757.htaOffline JayTHL
2020-03-27 16:48:03http://185.242.104.78/wftp/out-756898907.htaOffline JayTHL
2020-03-27 07:42:12http://185.242.104.78/wftp/ekeneeee_encrypted_C...Offlineencrypted GuLoader ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-03-27 16:48:11a053245e1ca52d72e986588fb061473547391c5f5fe3d14c40877370a1decaf8unknown  
2020-03-27 16:48:0895d546cb6ae084cd6e353c0bce321497e84d0c80ed2015019e7cd8472b3a3a86unknown  
2020-03-27 07:42:1259cccd461943d5e77b63666da5ec1d4893c1e7053fa07bcf720b63a3f7d23e03unknown