URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.152.166
Firstseen:2021-03-03 17:59:04 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-03 17:59:06 192.3.152.166192-3-152-166-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-25 14:26:05http://192.3.152.166/hhh.exeOfflineAgentTesla ext exe abuse_ch
2021-03-23 10:53:05http://192.3.152.166/jkj.exeOfflineAgentTesla ext exe telegram ffforward
2021-03-18 18:51:05http://192.3.152.166/atat/tmt.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-10 10:02:08http://192.3.152.166/nino/unn.exeOfflineexe Formbook ext ffforward
2021-03-10 09:40:12http://192.3.152.166/son/kpk.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-09 15:15:26http://192.3.152.166/coro/mmc.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-03-09 12:36:03http://192.3.152.166/bmmb/ada.exeOfflineexe abuse_ch
2021-03-09 08:54:09http://192.3.152.166/ammua/bnb.exeOfflineexe Formbook ext ffforward
2021-03-09 08:21:05http://192.3.152.166/kmdch/non.exeOfflineexe Formbook ext mattdep_
2021-03-05 15:12:05http://192.3.152.166/kmdch/ama.exeOfflineAgentTesla ext exe Loki ext opendir abuse_ch
2021-03-04 12:04:07http://192.3.152.166/mkkkm/mom.exeOfflineAgentTesla ext exe abuse_ch
2021-03-03 17:59:06http://192.3.152.166/kmdch/lal.exeOfflineAgentTesla ext exe opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-03-25 14:26:0531b3cedda2035b9710e9e5d94aff7e38d72e784014fe02f7aca8b28263020b96exeAgentTesla
2021-03-23 19:44:40f92af92a9a58c941191e13ceb8a16b061ee450e832ac08f7fd837a0ae2d80bb1exeAgentTesla
2021-03-23 10:53:05be0f9a9ac8af276985ba7882157844bacc9c2c2ec845eb9f0369912b455d3615exeAgentTesla
2021-03-19 05:45:4585c23641539a99ea860c03d787b65de3860e5cc2e8fadc88cbfa9bbbb94b0fbeexeAgentTesla
2021-03-18 18:51:0576ee0580c6650d545c9541cdc5f9227779947fd8006cf7f6907dcfad9f099ceeexeAgentTesla
2021-03-10 10:02:07988d84650b91424e291cb84ef84433cbd4214622365b226d925d71ffda0bccb8exeFormbook
2021-03-10 09:40:128d48f366bafe9984163ca9070cdfc5e5ca8868aebe29fb13428f8553bbd4d99bexeAgentTesla
2021-03-10 08:47:068d48f366bafe9984163ca9070cdfc5e5ca8868aebe29fb13428f8553bbd4d99bexeAgentTesla
2021-03-10 08:45:05988d84650b91424e291cb84ef84433cbd4214622365b226d925d71ffda0bccb8exeFormbook
2021-03-09 17:47:37eb0907a11946efe82a6a3e2879ec4033a3bb61464da82f30780be11bb833ac9aexeAgentTesla
2021-03-09 15:17:295e03e3c0687c08d09b2a00cbd68c0965fb690d3d9cf1d3aa4bf48725f56ce0e0exeFormbook
2021-03-09 15:15:22775904d1d274498b8a95bc6b06d2a93b9b81a0b79147a29cb06e6a0c418399b7exeAgentTesla
2021-03-09 08:54:08fce92bfceb412418320ffab7f7736fb84fdd8e5d857771ce9674bcffa275c4b9exeFormbook
2021-03-05 15:12:05284d0d845f078e7406f90ae8df889f38ec90800ef0d1c4475d8be4014f796469exeAgentTesla
2021-03-04 13:40:258a135032685ececd8f43fa420ff29aa7a9667195116a9b66dbdfbb85eec049f1exeAgentTesla
2021-03-04 13:26:398a135032685ececd8f43fa420ff29aa7a9667195116a9b66dbdfbb85eec049f1exeAgentTesla
2021-03-04 12:04:0727ac9c73d4b8754ab44172a17f0823245f8f873a06b6d89fee7e925b9fb595d7exeAgentTesla
2021-03-04 05:41:2727ac9c73d4b8754ab44172a17f0823245f8f873a06b6d89fee7e925b9fb595d7exeAgentTesla
2021-03-03 17:59:057f0ea66dd72bb10bff78950f81838509cb29b28c3384ca0b7c1055b47cd3166eexeAgentTesla