URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.13.56
Firstseen:2021-05-26 12:45:03 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-05-26 12:45:05 192.3.13.56192-3-13-56-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-01 12:34:04http://192.3.13.56/img/nd.exeOfflineexe NanoCore ext zbetcheckin
2021-06-01 12:30:04http://192.3.13.56/img/mn.exeOfflineexe NanoCore ext zbetcheckin
2021-06-01 12:29:04http://192.3.13.56/img/kn.exeOfflineexe NanoCore ext zbetcheckin
2021-06-01 11:29:09http://192.3.13.56/dashboard/docs/images/bug.xlsxOfflineNanoCore ext opendir xlsx abuse_ch
2021-06-01 11:29:04http://192.3.13.56/dashboard/docs/images/new.exeOfflineexe NanoCore ext opendir rat abuse_ch
2021-05-31 06:40:04http://192.3.13.56/dashboard/zh_cn/covid%20old.exeOfflineexe NanoCore ext opendir abuse_ch
2021-05-26 12:45:05http://192.3.13.56/dashboard/zh_cn/covid.exeOfflineexe NanoCore ext opendir abuse_ch
2021-05-26 12:45:05http://192.3.13.56/dashboard/zh_cn/usa.exeOfflineexe NanoCore ext opendir rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-06-06 22:14:43818df1108e8b47a339511b3e58ad95b46bbba2d41e59b30c1dedcf8f7650bfefexeNanoCore
2021-06-03 19:34:2770ce901a087e1bbe46d0b2caa61c46800a4935dc6886ef9baac14bd6e91b2abfexeNanoCore
2021-06-03 16:25:4270ce901a087e1bbe46d0b2caa61c46800a4935dc6886ef9baac14bd6e91b2abfexeNanoCore
2021-06-01 12:34:0463293e2c954c974e685dcb975d009448838d0ed659719d29340b587cc89c203fexeNanoCore
2021-06-01 12:30:0463293e2c954c974e685dcb975d009448838d0ed659719d29340b587cc89c203fexeNanoCore
2021-06-01 12:29:0463293e2c954c974e685dcb975d009448838d0ed659719d29340b587cc89c203fexeNanoCore
2021-06-01 11:29:0946470e5d1165ebd652727c2eb110e7955691a0d374d24929d481aaf9848f442bunknownNanoCore
2021-06-01 11:29:0474b44a4a01084396665ec50ef4a57adb40419f0996bc8723e1cfcd2ce975c06fexeNanoCore
2021-05-31 06:40:04df6dc86d7d3af52012925193704ab594844739b107f8e635dd4f46aa4aa4d5d6exeNanoCore
2021-05-30 22:59:52d0a381bd72a983718b806c00bb42ed91becdbbd43f79c0347bf7e1e56a2d6dafexeNanoCore
2021-05-30 22:56:17d0a381bd72a983718b806c00bb42ed91becdbbd43f79c0347bf7e1e56a2d6dafexeNanoCore
2021-05-30 22:28:224a0597ff1b659c692b07b848ea3893e93584bb8607810d32da4704ba85f91559exeNanoCore
2021-05-30 22:28:084a0597ff1b659c692b07b848ea3893e93584bb8607810d32da4704ba85f91559exeNanoCore
2021-05-28 06:17:3163293e2c954c974e685dcb975d009448838d0ed659719d29340b587cc89c203fexeNanoCore
2021-05-27 13:22:0763293e2c954c974e685dcb975d009448838d0ed659719d29340b587cc89c203fexeNanoCore
2021-05-27 11:28:409897b70f55d14fe5bf7ef5170ff83257fa5800361c953584982f7437239f19f6exeNanoCore
2021-05-27 06:32:59408eb0b0d835fd9b2fb9c5d274def10ac5f94eb77bed666dff3dd67f8cac0da8exeNanoCore
2021-05-27 06:32:22408eb0b0d835fd9b2fb9c5d274def10ac5f94eb77bed666dff3dd67f8cac0da8exeNanoCore
2021-05-26 23:41:32df6dc86d7d3af52012925193704ab594844739b107f8e635dd4f46aa4aa4d5d6exeNanoCore
2021-05-26 23:38:03df6dc86d7d3af52012925193704ab594844739b107f8e635dd4f46aa4aa4d5d6exeNanoCore
2021-05-26 23:27:297a13232aa6568a9f5e4aa0bbc83ff8123517abd0e69b5cbd174ca23fd290f117exeNanoCore
2021-05-26 23:18:177a13232aa6568a9f5e4aa0bbc83ff8123517abd0e69b5cbd174ca23fd290f117exeNanoCore
2021-05-26 12:45:059f96527c9f839559485e89c5c5ff8f95708035fd55c9fac0c2edf3764224d860exeNanoCore
2021-05-26 12:45:059f96527c9f839559485e89c5c5ff8f95708035fd55c9fac0c2edf3764224d860exeNanoCore