URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.176.138
Firstseen:2024-08-06 06:00:05 UTC
Total malware sites :27
Online malware sites :0 (0%)
Offline Malware sites :27 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-06 06:00:08 192.3.176.138192-3-176-138-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-20 08:12:34http://192.3.176.138/40/sihost.exeOffline abuse_ch
2025-03-20 08:12:04http://192.3.176.138/xampp/wfc/seven.htaOffline abuse_ch
2024-08-18 11:46:05http://192.3.176.138/xampp/sop/40.htaOfflinehta SnakeKeylogger ext abuse_ch
2024-08-15 13:41:06http://192.3.176.138/70/asusns.exeOfflineexe SnakeKeylogger ext James_inthe_box
2024-08-13 06:34:07https://192.3.176.138/32/sahost.exeOfflineexe opendir SnakeKeylogger ext NDA0E
2024-08-13 06:33:06http://192.3.176.138/32/sahost.exeOfflineexe opendir SnakeKeylogger ext NDA0E
2024-08-13 06:33:06http://192.3.176.138/xampp/sgr/ieexplore.htaOfflinehta SnakeKeylogger ext NDA0E
2024-08-13 06:33:06https://192.3.176.138/xampp/sgr/ieexplore.htaOfflinehta SnakeKeylogger ext NDA0E
2024-08-10 11:40:07https://192.3.176.138/107/sahost.exeOfflineexe SnakeKeylogger ext NDA0E
2024-08-10 07:34:13http://192.3.176.138/108/sahost.exeOfflineexe abus3reports
2024-08-10 07:25:07http://192.3.176.138/107/sahost.exeOfflineSnakeKeylogger ext abuse_ch
2024-08-09 06:58:04http://192.3.176.138/xampp/zoom/107.htaOfflineSnakeKeylogger ext abuse_ch
2024-08-07 18:43:05http://192.3.176.138/xampp/bhn/95.htaOffline abus3reports
2024-08-07 18:43:05http://192.3.176.138/xampp/zmo/zm/70.htaOffline abus3reports
2024-08-07 18:43:05http://192.3.176.138/xampp/ienet/ien/55.htaOffline abus3reports
2024-08-07 18:43:05http://192.3.176.138/xampp/ozon/oz/106.htaOfflineSnakeKeylogger ext abus3reports
2024-08-07 18:43:03http://192.3.176.138/xampp/euh/easywayformadeth...Offline abus3reports
2024-08-07 18:43:03http://192.3.176.138/xampp/euh/eu/easywayformad...Offline abus3reports
2024-08-07 18:38:13http://192.3.176.138/60/sahost.exeOfflineexe SnakeKeylogger ext abus3reports
2024-08-07 18:38:06http://192.3.176.138/55/sahost.exeOfflineexe SnakeKeylogger ext abus3reports
2024-08-07 18:38:05http://192.3.176.138/70/sahost.exeOfflineexe SnakeKeylogger ext abus3reports
2024-08-07 18:38:05http://192.3.176.138/95/sahost.exeOfflineexe SnakeKeylogger ext abus3reports
2024-08-07 14:29:06http://192.3.176.138/105/sahost.exeOfflineSnakeKeylogger ext James_inthe_box
2024-08-07 14:29:06http://192.3.176.138/106/sahost.exeOfflineSnakeKeylogger ext James_inthe_box
2024-08-07 06:52:05http://192.3.176.138/xampp/zmo/60.htaOffline abuse_ch
2024-08-06 06:00:08http://192.3.176.138/xampp/bhn/bh/90.htaOfflineAgentTesla ext hta abuse_ch
2024-08-06 06:00:08http://192.3.176.138/90/sahost.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-18 11:46:05862835269bbd12fe394cdb9ab03e9e87d7117480150b7bc3a84dcf7ebee3d1fehta SnakeKeylogger
2024-08-15 13:41:06e5797ef4bea22b1d24a9147c48726e9960ffa1b5866e04c11de117531483fe9dexe SnakeKeylogger
2024-08-13 06:34:079238f0f88af5a6f80f79c66f502b73ca920522f58128428bc556054963ea6d1cexeSnakeKeylogger
2024-08-13 06:33:069238f0f88af5a6f80f79c66f502b73ca920522f58128428bc556054963ea6d1cexeSnakeKeylogger
2024-08-13 06:33:06244449e74ef406c849ff28afed6e7c681f9879bdcda2a5218da777b7ad4c8046hta  
2024-08-13 06:33:06244449e74ef406c849ff28afed6e7c681f9879bdcda2a5218da777b7ad4c8046hta  
2024-08-10 11:40:07484e5a871ad69d6b214a31a3b7f8cfced71ba7a07e62205a90515f350cc0f723exeSnakeKeylogger
2024-08-10 07:34:128af777d0f92cef2d9040a634527c3753669235589c23129f09855ad0ebe10c6fexe 
2024-08-10 07:25:07484e5a871ad69d6b214a31a3b7f8cfced71ba7a07e62205a90515f350cc0f723exeSnakeKeylogger
2024-08-09 06:58:046f6a660ce89f6ea5bbe532921ddc4aa17bcd3f2524aa2461d4be265c9e7328b9htaSnakeKeylogger
2024-08-07 23:29:253513fc3dfdaf3deb1ed4252e43913b058ec12ae50bf9067016dba7df17f2ff03exe SnakeKeylogger
2024-08-07 20:48:20d4bc9adca2555a946c995d6c4dfee58147b21804003d645a055a3134b19a27ddexeSnakeKeylogger
2024-08-07 18:43:05daaa4c8b42e0af2debe7066de736b36b0d5502d16df81240d8d5295a46734f7fhta  
2024-08-07 18:43:0569e9ecf821d58b2e032e5174371a01ae58a96be37857eb2238a3106c827a5c7bhta  
2024-08-07 18:43:05f08e2102f102dedbe0201b769476574a353b972812d4126474124dc4f6b76c4fhta  
2024-08-07 18:43:04e26883bd5c9f0a2f8675c3331cae5eda33ea5432bbe2a47ebbd160106ef1acffhtaSnakeKeylogger
2024-08-07 18:38:13ce9429f517f80c390c71168ea43ad578e7fff7acff1abfa50d8167bad73304a8exeSnakeKeylogger
2024-08-07 18:38:0650e59bcfb26bd248b9d979be95aba9a034cc4481bd592c83f26fef033f8f83f0exeSnakeKeylogger
2024-08-07 18:38:0550e59bcfb26bd248b9d979be95aba9a034cc4481bd592c83f26fef033f8f83f0exeSnakeKeylogger
2024-08-07 18:38:0550e59bcfb26bd248b9d979be95aba9a034cc4481bd592c83f26fef033f8f83f0exeSnakeKeylogger
2024-08-07 14:29:069f7e2df5f136561e2c0bc3d0c32e70ee27073767dff963e592b749d8241df5d2exeSnakeKeylogger
2024-08-07 14:29:06d9863b7b710599bc2b308a0b78970da8c42ee5bc6d3dcda05c2de52a88125726exeSnakeKeylogger
2024-08-07 06:52:05d28a7a6f76de0727b7c5a34c184acfbc94f15501bb946489d1187fa906902ffehta  
2024-08-06 06:00:0894b67846d37007341608fe74d27d1ae0298d558d573a172d9013c42828eaa14aexeAgentTesla
2024-08-06 06:00:0777372e54cb633d52685ad88856e39d9e22b2efffd19293b4aca7fa9157f989a8htaAgentTesla