URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 194.58.103.2
Firstseen:2021-06-28 05:40:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-06-28 05:40:06 194.58.103.2194-58-103-2.cloudvps.regruhosting.ruNot listedAS197695 AS-REGRU- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-28 05:40:07http://194.58.103.2/main/vshosts.exeOfflinebitrat ext exe abuse_ch
2021-06-28 05:40:06http://194.58.103.2/main/chromium_.exeOfflineexe RedLineStealer ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-06-28 05:40:072448bed4db497e26e9def8dc20369bfd843bcb0e73dab435fe61ead1cc2f869aexeBitRAT
2021-06-28 05:40:055f737f1b5a908056939a3a813db4ed653b887c4e67fc19fab9cd72a9a3c748daexeRedLineStealer