URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 194.49.94.97
Firstseen:2022-12-02 08:45:06 UTC
Total malware sites :15
Online malware sites :0 (0%)
Offline Malware sites :15 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-12-02 08:45:12 194.49.94.97Not listedAS213035 AS-SERVERION- BGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-24 14:43:06http://194.49.94.97/ww/installation_speed.exeOfflinedropped-by-PrivateLoader Lumma LummaStealer andretavare5
2023-11-24 09:17:06http://194.49.94.97/ww/ffs.exeOfflinedropped-by-PrivateLoader eternity RedLine ext RedLineStealer ext andretavare5
2023-11-22 13:03:05http://194.49.94.97/ww/1.exeOfflinedropped-by-PrivateLoader RedLine ext RedLineStealer ext andretavare5
2023-11-15 01:11:08http://194.49.94.97/test/crypted.exeOffline32 exe RedLineStealer ext zbetcheckin
2023-11-14 07:59:07http://194.49.94.97/download/Service_32.exeOfflinedropped-by-PrivateLoader PrivateLoader andretavare5
2023-11-07 08:11:07http://194.49.94.97/download/ext/taskman.pngOffline JAMESWT_MHT
2023-11-07 08:11:07http://194.49.94.97/download/rise/StealerClient...Offlinerisepro RiseProStealer JAMESWT_MHT
2023-11-07 08:11:07http://194.49.94.97/download/rise/StealerClient...Offlinerisepro RiseProStealer JAMESWT_MHT
2023-11-07 08:11:07http://194.49.94.97/download/ext/taskman.jpegOffline JAMESWT_MHT
2023-11-07 08:10:26http://194.49.94.97/download/WWW14_64.exeOfflinePrivateLoader RedLineStealer ext Smoke Loader ext JAMESWT_MHT
2023-11-07 08:10:23http://194.49.94.97/download/ext/cute_goats.jpegOffline JAMESWT_MHT
2023-11-07 08:10:21http://194.49.94.97/download/ext/cute_goats.pngOffline JAMESWT_MHT
2023-11-06 12:16:07http://194.49.94.97/download/Services.exeOfflinedropped-by-PrivateLoader PrivateLoader andretavare5
2022-12-03 03:57:04http://194.49.94.97/oso/fbuche.exeOfflineexe Formbook ext jstrosch
2022-12-02 08:45:12http://194.49.94.97/oso/fbhans.exeOfflineexe Formbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-24 14:43:0692abdb4b98aada22772501d4fa60457184ad5a71e07667f06ebd2e9aef53a6b6exeLummaStealer
2023-11-24 09:52:12172c25ce4a5916f38026250b5799b318751216eb858a6b1230b039527115af52exeSmoke Loader
2023-11-24 09:17:06c6fbb7022c7beb3b4c840cb4d46b35f237a29ef70d6c400e673eedc55698d3c4exeRedLineStealer
2023-11-24 00:08:04739219ab2729b639d38c00e92f9e80aebc3073a353a0ed135fe65d5fa5130261exe  
2023-11-23 11:34:0399c7f829c90f7086b2092834ebe55a66b442bda9edd63b3ee553a70caf9993dcexe  
2023-11-23 11:21:538567834f78a0d21d37387da756af49e40dd379d46b4a556d689d00e9292498fcexe RiseProStealer
2023-11-23 11:03:58b164abb77d90760b780f7373370a8ca068a56cbbf7366404d7add38a9eef7b2aexe  
2023-11-23 10:45:55c116225b7787310fde18c8c0a9d9c01667f57f41174fdf5c8c56fab56f689990exe  
2023-11-23 10:25:2257ac0b79b98d29972b32b1029514429658e0d1022c0d8419a63fb46fe57dccffexe  
2023-11-23 09:52:2084e08a8f04c1518ad6dd6f5493d3afe48571916b46f504a08b208375657ab900exe  
2023-11-22 13:03:05e3ba3128521529aa94345e7afbff46bee7a4c38eadce2e4f3a931afb22fad365exeRedLineStealer
2023-11-15 01:11:08525b154b2bae8eda0627e58af0dbeaceda5cd83589a7d697700a9bc9780d8940exeRedLineStealer
2023-11-14 07:59:072cb5b2678054dd2f1b93d37a96b927830c4a7da699f061adee370807088257deexePrivateLoader
2023-11-14 06:27:00d61c704820a6336a6e625f5f6800c56755c030fd4c16d749648eeb2196bdd85aexe RiseProStealer
2023-11-14 06:06:385f9b962629b3eabbf190c2e0982062e3d795261cc209477e88f1d8c6ba016b08exe RiseProStealer
2023-11-14 05:17:079713f8c775f3ad83ffbb0987c83f7dc5bbc8646290c4a84c77e225d1d486969cexe  
2023-11-12 17:48:4976961b32dfaa92f07b0cdf92f0b45c7e3c9acde075aeb30197e56bd3cce4c6afexe PrivateLoader
2023-11-07 08:11:072f5370312110028e933cdcb12b331523010b79293fc924ec3ff316ffcafdef23exe RisePro
2023-11-07 08:11:07e9b536aa0db7a67f4ac4c3aaf2dbc0063da7494f83a93805cfc8ad8cf1278d06crx  
2023-11-07 08:11:07a831bdc4cc298ed6563d6b3c1b0124dd4efdb71fc00af3f0a4894c1dd334350fexeRisePro
2023-11-07 08:11:07a0f686dbb672bc46820508a35b5f8b16d0b6b55e9db5fa75ac0c88323206a05fjson  
2023-11-07 08:10:261f0a1a7674ad868c99421fc13b0457de7ab612ca5948ae7cd045db355720e1fdexe RedLineStealer
2023-11-07 08:10:22f0e8b7edf6de351ce20523a139205cc8adc8321a1dc932ebb8e8fb0206b55e18crx  
2023-11-07 08:10:20247194daa85b200be352b03689ccfa68d3a5d4a0ca5a47f6f91f39a90d417b73json  
2023-11-06 12:16:07c6185a23c51b8ac77e6c1bdf2cd4a8d39b02af8b8027d4162cf9766d19cf87c8exePrivateLoader
2022-12-03 03:57:040646127a521c320e61c31e4ae2c035e53438d7ff8d25e28cd7150367f40d9504exeFormbook
2022-12-02 08:45:063cfd81b824673a6ba23d472bd09d5e7610a3346cce6f23956507af5eab63c012exeFormbook