URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 194.50.153.183
Firstseen:2023-07-07 18:21:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-07-07 18:21:08 194.50.153.183Not listedAS216024 KVMKA-COM- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-07-21 07:44:12http://194.50.153.183/svchost.exeOfflineexe LaplasClipper abuse_ch
2023-07-07 18:21:08http://194.50.153.183/conhost.exeOffline32 CoinMiner exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-07-26 20:49:03c60ecd5714a23a727d9749652883ec95bcdb350b9f278c34ac504edb898073e4exeCoinMiner
2023-07-22 16:26:15ca11d0fef6aad8481e038660b5ad9b8be14614b46be2a624e630b446749d581fexe CoinMiner
2023-07-21 07:44:122c63c61e0adaaf669c9c674edfc9081d415c05b834611944a682f120ab9559d8exeLaplasClipper
2023-07-13 19:41:4228725b63a75a38a88b1663d49d4ba43ab917ba0d0ce6b700c64be2fefd8ffa8fexe  
2023-07-07 18:21:08cdffe175d69a7b4c7fb9e7fa2aef3f266ce8af7d03d3859ec5b3f82cb72c9797exe