URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 194.226.139.141
Firstseen:2021-07-29 08:50:03 UTC
Total malware sites :37
Online malware sites :0 (0%)
Offline Malware sites :37 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-07-29 08:50:07 194.226.139.141Not listedAS50214 QWARTA- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-08-07 21:10:04http://194.226.139.141/Slipstream.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-07 17:05:07http://194.226.139.141/spamer.exeOfflineexe zbetcheckin
2021-08-07 09:00:04http://194.226.139.141/123.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-07 09:00:04http://194.226.139.141/xvpn.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-07 05:19:03http://194.226.139.141/@JuicyFruicy1.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-07 01:40:10http://194.226.139.141/NixwareLoadAdd.exeOffline32 CoinMiner.XMRig exe zbetcheckin
2021-08-07 00:55:04http://194.226.139.141/installs.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-04 18:11:05http://194.226.139.141/CryMore2.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-04 14:34:05http://194.226.139.141/cheat.exeOffline32 dcrat exe zbetcheckin
2021-08-04 10:11:04http://194.226.139.141/R3K3GVYVPP.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-04 10:11:04http://194.226.139.141/SessionCrtSvcWinrefCrt.exeOffline32 dcrat exe zbetcheckin
2021-08-04 08:46:04http://194.226.139.141/Clickerman.exeOfflineexe RedLineStealer ext vxvault
2021-08-02 20:43:03http://194.226.139.141/zzz.exeOffline32 dcrat exe zbetcheckin
2021-08-02 16:21:03http://194.226.139.141/babkaaepta.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-02 08:33:05http://194.226.139.141/fontWinRuntimecrtNetrefr...Offline32 dcrat exe zbetcheckin
2021-08-01 22:00:04http://194.226.139.141/eacing.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-01 21:48:04http://194.226.139.141/z.exeOffline32 exe PandaStealer RedLineStealer ext zbetcheckin
2021-08-01 18:41:04http://194.226.139.141/kazah.exeOffline32 exe zbetcheckin
2021-07-31 21:01:04http://194.226.139.141/@Stewor.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-31 17:50:04http://194.226.139.141/smoke.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-31 03:24:03http://194.226.139.141/@sc4lly1337.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-31 00:12:04http://194.226.139.141/YTtraffic.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-31 00:12:04http://194.226.139.141/inhack.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-30 19:50:05http://194.226.139.141/intonetrefruntimedhcp.exeOffline32 dcrat exe zbetcheckin
2021-07-30 19:46:05http://194.226.139.141/huh.exeOffline32 AgentTesla ext exe zbetcheckin
2021-07-30 15:56:05http://194.226.139.141/fontSessionRuntimehostNe...Offline32 dcrat exe zbetcheckin
2021-07-29 11:30:08http://194.226.139.141/Desktop.exeOffline32 dcrat exe zbetcheckin
2021-07-29 11:30:05http://194.226.139.141/0GTTI98V0N.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-29 11:30:05http://194.226.139.141/brokerhostperffontSavesd...Offline32 dcrat exe zbetcheckin
2021-07-29 11:30:04http://194.226.139.141/@bbakoch.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-29 11:30:04http://194.226.139.141/@worker2005.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-29 11:29:06http://194.226.139.141/reviewwinfontrefperf.exeOffline32 dcrat exe zbetcheckin
2021-07-29 11:29:05http://194.226.139.141/bvack.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-29 11:29:04http://194.226.139.141/Minerrr.exeOfflineexe zbetcheckin
2021-07-29 11:17:04http://194.226.139.141/DhcpcommonFontsession.exeOffline32 dcrat exe zbetcheckin
2021-07-29 11:17:04http://194.226.139.141/babkadeda.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-07-29 08:50:07http://194.226.139.141/SessionBrokerhostCrtComm...Offlinedcrat exe vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-08 21:40:506b647f3a457418adc81233af2a8874965abbd94e9eb1aba6ea70141e65227c77exe  
2021-08-08 20:29:42f4eeda796f0b2d3be80b0d3d8d1ea069d097fd772c8961adc402d86b63ab22b1exe  
2021-08-08 18:44:5042a0d3693b70f8697407eff8ecf05a9eec43054b457d0537c8807288f54b31b9exe  
2021-08-08 14:41:115b79d6a89eae0449e2cd5732ecabe7b47a482c737c196913b43122e7ad4eb1a4exe  
2021-08-08 05:46:108f8efcd4031721a458abbf5a0e164eb9d318fe8f5a16c5d1a174e13125128539exe 
2021-08-08 03:35:42a5fa1ba4bfdb8f556d58ddd6ae57eb1dc8f233fbefa19ba0591f611df819dec1exe  
2021-08-08 02:22:459439f5c9159c444779e9c01bd54499de6bf89452c290135786de3fe26b786358exe  
2021-08-08 00:34:46d410282ce2b3c4db3aebd82851efdb3cbb8d9660e9dce29fd4eb2fcff4a2a7cbexe  
2021-08-08 00:34:27257e21ce6d8499875ac26df9a47b91086df692b7da720bafc1c11a8120065a28exe  
2021-08-07 23:40:31e106f24a8f354f239c8facb587163ad2d5f5a25f201ff1ff46d449cc43e29440exe  
2021-08-07 21:10:046f14afbba1fb3f07259d7153604a7877f9a0be968b600e2f82b6b491d4e994a6exeRedLineStealer
2021-08-07 17:05:078d11da2582a4e82ff7ca02288211613a1f7326b7426eb245138a1160e3dddfb4exe 
2021-08-07 09:00:04aa3ef811cfeacbe782715219b91eb5f798780b6e81a3dd31eb4c2a8851689b54exeRedLineStealer
2021-08-07 09:00:047b1233e19c3bac48a1f49ec33923f7504efaa20fb5b798ff9a00f73cbc2422c1exeRedLineStealer
2021-08-07 05:19:03ddaa218a629d5d9c1cbc4158b6fba8f0e02c6bfa58afb79cb87947aef81e062dexeRedLineStealer
2021-08-07 01:40:106a0d05477e23fc1152067fc51d50a044bccf0e0a0654dbae1864df792400e935exeCoinMiner.XMRig
2021-08-07 00:55:048cbafd04f32cc48843fcac1913ae731b04e990a44d789a74b0ef50785874d5aaexeRedLineStealer
2021-08-06 11:16:437d707014985dc627d9bde0394a3e8945b7e2e1ae8301bb87e4ab5598672d37d8exeRedLineStealer
2021-08-04 18:11:05ee634bdc72e1a5b57eb1f7d42e5d0a4b7c9b1f7aa53a1f53564bf4ff5c74361aexeRedLineStealer
2021-08-04 17:09:07cc88099e43bfc20ce5bb399890fa488d4aabd79b9d0d5e25cf5347212bd47ae3exe  
2021-08-04 14:34:050fd328ebdc2e6046e737da5425f4566b31d4f61df765d530f5faed982e2d47caexeDCRat
2021-08-04 10:11:04c743cf5260e759fe10138fe432eb1fc8e633559ca94798dbd24cc632413c2c8eexeRedLineStealer
2021-08-04 10:11:0436d1497c536921f332a26558c9eff42f6502bf5ffec6710f4b50e35f98e627aaexeDCRat
2021-08-04 08:46:04eafab555da9e8598c75b806109e20bcc36326ea3a018536dfac29b7ec71b6e61exeRedLineStealer
2021-08-02 20:43:032f1ba0d2a1aaa17d2a8f8f9f97b9f553b1dc9e7d32039cf36382bddcebbfdaefexeDCRat
2021-08-02 16:21:036f14dcd1c276f021ae900501a048f461ff849ef59dbc860339911a28ace7c757exeRedLineStealer
2021-08-02 15:09:3169565e54f5b9348e0100c26c17fb1824c72bc96bd594594fa56b5a6c8ac54d4bexe  
2021-08-02 08:33:05dd9d370fbb04aeef33b7a4e0e633b0613f54e8a971bf506e0efc2ac5de107c20exeDCRat
2021-08-01 22:00:04dcaf58a74327239aff106eb7da1f06a9ad9bceeaad4e8a08496fa75f744e8f55exeRedLineStealer
2021-08-01 21:48:0471e5de30f627eacb124f9f11d7ba70de43997847e88a61e440593ef9fd776babexePandaStealer
2021-08-01 18:41:04bb5f523d4b4d9a8bfb0f0e89eff3559d228451476467b7b193e7686031398d3dexePoullight
2021-08-01 18:39:05f37637c8712fa85c934eaa75f050d15c4156a795125f013b2eada06bc9ee2d64exe DCRat
2021-07-31 22:37:10e7e2866ed8e4e76df821c19dee3c8b3c41c282c226152e5b3abc352d2f2a6861exe 
2021-07-31 21:01:041d928c0f640e731208adc0736aca791af0ba7e7dfdad0800d9de2fc968ef0010exeRedLineStealer
2021-07-31 17:50:04215fe6cb15f087bb8c0b5e33437317cb94bd8902bd3027aeadcda78329518441exeRedLineStealer
2021-07-31 13:50:10c44f4f19f854e3a7312d262f8225024d3eb235fc580f4175ab923a4acd0231ffexeRedLineStealer
2021-07-31 03:24:036da210965cd769856bbcb8bb501abf25c832f0f6a70e73240436629ce6362fa9exeRedLineStealer
2021-07-31 00:12:040c273b2f59c6218f70464a8cf489e620f803559baa1d1e69b8c6dec7b7bd7a1dexeRedLineStealer
2021-07-31 00:12:04a9413d0e72606171e933d573c31949d552662e4bb62461b12840ab6c8e008c6eexeRedLineStealer
2021-07-30 19:50:05d6f77ffe0af94a159322e345040797c44aba43f2188c82a341dc8efc3fa216fdexeDCRat
2021-07-30 19:46:051a4284cd084b609aa03892894e379c630505b5e4b9ccfc278138d36668f4526fexeAgentTesla
2021-07-30 15:56:05bdeb14ad6ce1ac8539d4b937c593ae706826fd3732ad506de5189521eea43643exeDCRat
2021-07-30 04:29:49630b568c36cd9ad05dd5bf5c9c60e95493084820b1996e3d41407cf05c8b67bbexe 
2021-07-29 11:30:083ab850d582976fd9c1bb14c1c50cffa66e9fd6e55fc27a704f01c45d1bc251dcexeDCRat
2021-07-29 11:30:05d632932299301c0e00fb74d348ebca88a6a5d0636abbe4994c9a0c7dc6e8ecfaexeRedLineStealer
2021-07-29 11:30:0564372c3ad1a4fff52786f20761db9c67605a533f0b5c48311b9cb005c24e0314exeDCRat
2021-07-29 11:30:046e4f20b04fee92074f9d640a80ebf28c27510e89c20cbd3c66f00a3ec2fd3989exeRedLineStealer
2021-07-29 11:30:04cc2cc6baae7dea7349b52df05fe18659ee0e85750020ce2592c1e433686cd4e4exeRedLineStealer
2021-07-29 11:29:0623b110e0a381abb4d44bd7e2906548429ee426d9463a02af31dc3dd98c044341exeDCRat
2021-07-29 11:29:05d34e796266410aff6fcad07b74545d3121bfc595cadef5370c01153b4dbf0047exeRedLineStealer
2021-07-29 11:29:04e5ebf928e029cbd3799e7db55f61252e11ab3a821a5998b9044c0ea76aa65b20exe 
2021-07-29 11:17:045c08819a0402013e935fb78e6349ea1a798c53db14e482267deaf183b06dc436exeDCRat
2021-07-29 11:17:04cfead95d7c8a5769d14c2d5cf989237af61be10241de21523f8a955e5b36f1e7exeRedLineStealer
2021-07-29 08:50:061d50e2d78f933c77c53253df393839673c730d3aed70610b579bd178aed3a1ffexeDCRat