URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.26.143
Firstseen:2025-04-15 09:42:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-15 09:42:06 192.3.26.143192-3-26-143-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-15 09:44:06http://192.3.26.143/460/csrss.exeOfflineexe MassLogger ext opendir abuse_ch
2025-04-15 09:43:05http://192.3.26.143/440/hkcmd.exeOfflineDBatLoader ext exe Formbook ext opendir abuse_ch
2025-04-15 09:42:06http://192.3.26.143/470/csrss.exeOfflineexe Formbook ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-15 09:44:06f919ad3a0b960e8665024b04de0d5e9b9b8bcfd50276cb6ad03ac3a5ff8f1a48exeMassLogger
2025-04-15 09:43:0400b229de51c409d79b0084465543c9197f797d4a835290ebf72cbce75cfb2044exeDBatLoader
2025-04-15 09:42:06cfecc683911218dde9c607fc0365c31c3fa5e4f7561cb7a68bc99c96c68bf0a4exeFormbook