URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.109.200.5
Firstseen:2026-02-09 12:54:05 UTC
Total malware sites :25
Online malware sites :22 (88%)
Offline Malware sites :3 (12%)
Newest active malware site :2026-02-09 12:55:17 UTC
Oldest active malware site :2026-02-09 12:54:09 UTC (Age: 1 day, 2 hours, 17 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-09 12:54:09 192.109.200.5tl-vpn.ptr.networkSBL692428AS51396 PFCLOUD- SEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-09 12:55:17http://192.109.200.5/webb/YELLOW.ps1Online abuse_ch
2026-02-09 12:55:17http://192.109.200.5/webb/wes.ps1Online abuse_ch
2026-02-09 12:55:17http://192.109.200.5/webb/we.ps1Online abuse_ch
2026-02-09 12:55:17http://192.109.200.5/webb/gabi.ps1OfflinePureLogsStealer abuse_ch
2026-02-09 12:55:17http://192.109.200.5/webb/ytoto.ps1Online abuse_ch
2026-02-09 12:55:16http://192.109.200.5/webb/AFRICA.ps1Online abuse_ch
2026-02-09 12:55:16http://192.109.200.5/webb/ENCRYPTED.ps1Online abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/VV.ps1OnlineAgentTesla ext abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/testttt.ps1Online abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/cryptedwe.jsOnline abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/crypted.jsOnline abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/mari.ps1OnlineRemcosRAT ext abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/STE2.ps1Online abuse_ch
2026-02-09 12:55:14http://192.109.200.5/webb/testnewwwww.ps1Offline abuse_ch
2026-02-09 12:55:11http://192.109.200.5/webb/VAL.ps1Offline abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/fla.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/goodies.ps1Onlineascii opendir powershell ps1 RemcosRAT ext abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/CLASS.ps1OnlineAgentTesla ext ascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/STE.ps1OnlineAgentTesla ext ascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/iyke.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/oracle.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:10http://192.109.200.5/webb/RR.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:09http://192.109.200.5/webb/aryaa.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:09http://192.109.200.5/webb/CLASSS.ps1Onlineascii opendir powershell ps1 abuse_ch
2026-02-09 12:54:09http://192.109.200.5/webb/wizzy.ps1Onlineascii opendir powershell ps1 abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-09 12:55:1781cf0793a68ac6c58c6db0dc6107d7248c3b109b1413704abb2d9ede88b1078eps1  
2026-02-09 12:55:17aecb97d0a16a16534c9febbff6ef3b7a74dcf96026006c847b3c60ec97bf6bddps1  
2026-02-09 12:55:1700ea18a1378239cd69d3cfa069f27d71d46dee83dcca0e4dee9da66be22c5900ps1  
2026-02-09 12:55:17eafa0ebe69af75a617a9abb5bc72f05ab05cac2823441059aca1b57da3ca4dc6ps1PureLogsStealer
2026-02-09 12:55:17227ade72540772246e605e907417a3271776dedd9fd7d13c1144006396a8885cps1  
2026-02-09 12:55:164b2a48bad368a5618e2a10b7a764d51ef611c6de039c98d42c2263228bf7fcbdps1  
2026-02-09 12:55:15fdd3997cb7be3d6a28aae213dd174881ea3ae2145d00088ac502702c436450f6ps1  
2026-02-09 12:55:14654d55e150dbd013459a6025c3f0f32164041aa1c220beefd435c9b658a965c3ps1  
2026-02-09 12:55:1424e588854492e135b08e0f76756ec0299b4364c1f6160cd4790e1c67cb786b6dps1  
2026-02-09 12:55:1404df31dd342110b191d9c7c7f282d4de48b1ea6907f6914c6cb7cc67f612cb64js  
2026-02-09 12:55:1408dcf856f70b10328f57026c95f7639ecfa6d107b4b9eb23f51ef71831346dd4js  
2026-02-09 12:55:1414cf7023721b60f8eea452bc7d911f4c10bda79145116a16348b93c1fca2fe41ps1RemcosRAT
2026-02-09 12:55:142d581d37ae3765b1186fae654fcef9f4cd1d89950de2cc4c6ebfd942fdfd551cps1 AgentTesla
2026-02-09 12:54:10b318b59cb13c3d1242e2b32cf2432791b190ca8e8d705ec0967dd59e550fb15eps1  
2026-02-09 12:54:10a541da07df827b5b7dcf28aa2c0de13be65c5d0f7fa4a31a44c1a6ec75f9bbceps1 RemcosRAT
2026-02-09 12:54:10efc47e3cb0b0562ca13dad8e909e88dad19e6fa5dac755985db1292304152dd0ps1 AgentTesla
2026-02-09 12:54:10ac1dfb30280d47f317da7630ec01654477366ca9cc793f554d08ec592b2e0133ps1 AgentTesla
2026-02-09 12:54:10363faef6ab84a3a35fd525fdc20c5aed9a21c761ab2d29d1d5d0ccb17b3076e4ps1  
2026-02-09 12:54:1029330a348db563b93548f7972f3243da9af0300334ab8d9f7945c125c5cbfa7dps1  
2026-02-09 12:54:10d36d616625467e7c19941e364da99d26f54400b3742a1e562d3c9b834497f534ps1  
2026-02-09 12:54:096f077bf2e3a48a35e474d191115fa2e82f5a61e97d5218620ecffebad53328e5ps1  
2026-02-09 12:54:09858549d71075f2dc72246fafc8fdf3720c51e95098f047468dea8017ec651d81ps1  
2026-02-09 12:54:08a906b50d22eedc8ebd393bf050eaff6d21383fbb4c80430f9e285242f240cba2ps1