🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 193.149.187.81
Firstseen:2026-01-15 17:36:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-15 17:36:06 193.149.187.81Not listedAS399629 BLNWX- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-16 07:43:07http://193.149.187.81:1287/1.exeOfflineexe MeshAgent abuse_ch
2026-01-15 17:36:10http://193.149.187.81:8888/lnk/1.exeOfflinehuntio MeshAgent opendir ua-wget BlinkzSec
2026-01-15 17:36:07http://193.149.187.81:8888/exe.exeOfflinehuntio MeshAgent opendir ua-wget BlinkzSec
2026-01-15 17:36:06http://193.149.187.81:8888/lnk/a.batOfflinehuntio Loader MeshAgent opendir ua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-16 07:43:0739c4decc4881ec02a47cd01c0fd8c3030527b466124ad03c6f99cfaa0ba0b72eexeMeshAgent
2026-01-15 17:36:1039c4decc4881ec02a47cd01c0fd8c3030527b466124ad03c6f99cfaa0ba0b72eexeMeshAgent
2026-01-15 17:36:07bde5b0c082a903684d086caa4ebde2879ea2e6cdc2fbeb18d1f8d78e451ce7a5exeMeshAgent
2026-01-15 17:36:061bb1c2c4be89e0c88563bb0fccee5e16ff910695bba78c8c43f3259d3f3f8ff0batMeshAgent