URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.179.145
Firstseen:2024-01-22 11:45:06 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-01-22 11:45:09 192.3.179.145192-3-179-145-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-01 08:31:10http://192.3.179.145/45/SNK.txtOffline404KeyLogger ascii Encoded rev-base64-loader NDA0E
2024-08-01 07:51:04http://192.3.179.145/45/newlevelcreatedgirlseye...OfflineSnakeKeylogger ext vbs abuse_ch
2024-08-01 07:50:06http://192.3.179.145/45/kon/wethinkingentirethi...Offlinedoc SnakeKeylogger ext abuse_ch
2024-02-08 17:41:07http://192.3.179.145/T0802F/wininit.exeOfflineAgentTesla ext OriginLogger James_inthe_box
2024-01-22 11:45:09http://192.3.179.145/3101/IEupdates.vbsOfflinevbs abuse_ch
2024-01-22 11:45:09http://192.3.179.145/windows/microsoftunderstan...Offlinedoc abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-01 08:31:1016751cd7ad430f8c6bf21e469473814327035184ca6f9c9349f2dcc6c11cde07txt 404Keylogger
2024-08-01 07:50:065961a204bb43bb63f2b98836a34afd1e16a6f3cb160fd17b4718b377273255ffrtfSnakeKeylogger
2024-02-08 17:41:07df8a906a6a3fa7a3631b68f28d05854dbdf920ba3b16215049d8e1f020f82c75exeAgentTesla
2024-01-22 11:45:087389cc36ef42107c62154c8dc16e69ecc472ec2a6f502d8260bc1580b8217488unknown  
2024-01-22 11:45:08214aa2fddabe3e85814a2423ad9c0ec8810de0b5e15237c9fabb50a2467e3e75unknown