URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.99.135.162
Firstseen:2024-07-13 11:45:09 UTC
Total malware sites :32
Online malware sites :0 (0%)
Offline Malware sites :32 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-11-01 15:19:13http://185.99.135.162/update/TPB-1.exeOfflineVidar ext abus3reports
2024-07-13 12:39:35http://185.99.135.162/limetor/link4.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:35http://185.99.135.162/TPBActivetor/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:35http://185.99.135.162/HEXO-SOFTWARE/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:35http://185.99.135.162/FreeApps/link4.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:25http://185.99.135.162/1337/C.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:15http://185.99.135.162/TPBActivetor/link3.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:12http://185.99.135.162/1337/E.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:12http://185.99.135.162/1337/D.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:12http://185.99.135.162/FreeApps/link3.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:11http://185.99.135.162/1337/A.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:10http://185.99.135.162/TORRENT-SPAM/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:10http://185.99.135.162/TPBActivetor/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:10http://185.99.135.162/FreeApps/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:10http://185.99.135.162/TORRENT-SPAM/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/TPBActivetor/link4.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/HEXO-SOFTWARE/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/FreeApps/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/1337/B.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/limetor/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/limetor/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:39:09http://185.99.135.162/limetor/link3.txtOfflineascii link opendir NDA0E
2024-07-13 12:13:15http://185.99.135.162/newz2k/link4.txtOfflineascii link opendir NDA0E
2024-07-13 12:13:14http://185.99.135.162/newz2k/link2.txtOfflineascii link opendir NDA0E
2024-07-13 12:13:14http://185.99.135.162/newz2k/link.txtOfflineascii link opendir NDA0E
2024-07-13 12:13:13http://185.99.135.162/newz2k/link3.txtOfflineascii link opendir NDA0E
2024-07-13 11:52:34http://185.99.135.162/TPB-2-Links/link.txtOfflineascii link opendir NDA0E
2024-07-13 11:52:13http://185.99.135.162/TPB-2-Links/link2.txtOfflineascii link opendir NDA0E
2024-07-13 11:48:21http://185.99.135.162/TG-Source/link2.txtOfflineascii link opendir NDA0E
2024-07-13 11:48:14http://185.99.135.162/TG-Source/link.txtOfflineascii link opendir NDA0E
2024-07-13 11:45:17http://185.99.135.162/update/link.txtOfflineascii link opendir NDA0E
2024-07-13 11:45:17http://185.99.135.162/TPB-G/link.txtOfflineascii link opendir NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-11-19 00:59:5398f1e9d201c49c501fdb01a3f325d301dde90facccf219db61a35bf99fa38952exe Vidar
2024-11-11 10:17:39a2798b69026fb2332e89ddd9ba0ddb82b7d658231bf8e4edd2577e25b76a0395exe Vidar
2024-11-03 15:56:07912320095089137ef3327b9a9682a87966308e44217ab77234e7bf5475496419exe Vidar
2024-11-01 15:19:1318f5f368c18b9988c7d66abb169d54029cb6316910b109f3e3a4dbcc37a5b59cexeVidar