URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 188.81.134.196
Firstseen:2024-10-16 16:48:04 UTC
Total malware sites :2
Online malware sites :2 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2024-12-17 07:06:16 UTC
Oldest active malware site :2024-10-16 16:48:17 UTC (Age: 1 year, 7 month, 18 days, 7 hours, 23 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-10-16 16:48:17 188.81.134.196bl16-134-196.dsl.telepac.ptNot listedAS3243 MEO-RESIDENCIAL- PTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-17 07:06:16http://188.81.134.196/resources/js/info2R.txt/Onlinebase64 CoinMiner rev rev-base64-loader lontze7
2024-10-16 16:48:17http://188.81.134.196/resources/js/info2R.txtOnlinebase64 CoinMiner rev-base64-loader abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-12-17 07:06:16250743f1af4b5a9dd18028f792a0432a43d6bf17b50aad75b9d3a0c83786940dtxt CoinMiner
2024-12-16 23:04:240645f0a6ddb9632bf7303d53fe8b21b21f5a9f4bf739e17fa2b5068471bd685ctxt  
2024-10-16 16:48:17250743f1af4b5a9dd18028f792a0432a43d6bf17b50aad75b9d3a0c83786940dtxt CoinMiner