URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.227.158.96
Firstseen:2022-02-14 08:31:02 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-14 08:31:04 192.227.158.96192-227-158-96-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-01 17:49:06http://192.227.158.96/favour.exeOfflineAgentTesla ext exe abuse_ch
2022-03-01 09:00:07http://192.227.158.96/file.exeOfflineAgentTesla ext exe abuse_ch
2022-02-28 09:16:05http://192.227.158.96/aboy.exeOfflineAgentTesla ext exe abuse_ch
2022-02-24 08:16:05http://192.227.158.96/Ugo.exeOfflineAgentTesla ext exe abuse_ch
2022-02-23 13:06:04http://192.227.158.96/kok/GOD.exeOfflineAgentTesla ext exe opendir abuse_ch
2022-02-23 12:41:05http://192.227.158.96/dera.exeOfflineAgentTesla ext exe abuse_ch
2022-02-21 15:26:05http://192.227.158.96/fire.exeOfflineAgentTesla ext exe abuse_ch
2022-02-16 16:48:04http://192.227.158.96/jesus.exeOfflineAgentTesla ext exe abuse_ch
2022-02-14 08:31:04http://192.227.158.96/razy.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-01 17:49:060b96b48acc4dae991a46897dbf912ee78b04b81182e5948ab4c0dd5991bd9ab0exeAgentTesla
2022-03-01 09:00:0717a9af1769c088760c113fb2c361fa4e75d30d59d058340142697e8b93efb17fexeAgentTesla
2022-02-28 09:16:056b683a2061525fc4ce20765d8c3be94ef9bc09783fff6e463ed54433321823ebexeAgentTesla
2022-02-24 10:08:169583a4b3e4f4621fadda270e9d6a003f5e93dcf7228e4e2335b83d5d2b0d2714exeAgentTesla
2022-02-24 08:16:044f382a45ccadbea5c8c789f482cd8fd9bde3a87d43f47db8f6f8930e461d482aexeAgentTesla
2022-02-24 04:06:06d47fb2ff69549ce70bf24ec5b930a1d8f9d46dfbbe0b5f84fb2096cba10c2863exe 
2022-02-23 17:16:407eebc4f2ec92557e283772ccc07186c3b41062034a51b8c82ee0d0f21891eb37exeAgentTesla
2022-02-23 13:06:048180549a22a72478ca6caf24424a9d84f597efa78f85d10d8c8dc32a37fcb04bexeAgentTesla
2022-02-23 12:41:058180549a22a72478ca6caf24424a9d84f597efa78f85d10d8c8dc32a37fcb04bexeAgentTesla
2022-02-21 17:17:0211d6d606b19c9d0cea45156da313cc372a168022da8b31ad4d4596b8bee53c6dexeAgentTesla
2022-02-21 15:26:0542cdec13c066ea165a93d0fa328b3d8f26e563b8f5d0544634a60708f417ba78exeAgentTesla
2022-02-17 09:37:05dabba0dc8f8921f74b3c85de6a9ad8f9604a880158fb286acba5a67fd3eba406exeAgentTesla
2022-02-16 16:48:04afcf1462d6f1e811b0c9e0d5ccb4b6561a63a53a97c46ab99fe58b971617c9e2exeAgentTesla
2022-02-14 15:38:5425edda50ba9f239d1ab6cd2f5fd8f1736b11ef9cbcd7029f5ffde8442da4497bexe 
2022-02-14 08:31:0401b7ecba4c040bd3c352b2023e1f7f38c2b2ef741f23a91301153f03760d3505exeAgentTesla