URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 195.201.23.180
Firstseen:2023-02-06 13:19:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-06 13:19:10 195.201.23.180static.180.23.201.195.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-02-09 05:23:03http://195.201.23.180/apexframework64.exeOfflinedropped-by-amadey viql
2023-02-06 13:19:10http://195.201.23.180/urapwd2x.dllOfflineexe RaccoonStealer ext RecordBreaker ext vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-02-08 12:23:060b0a847563b9c7f7b8e12f322969ed4d50deb5046b3e3329dc0dbccb9c489450dll RecordBreaker
2023-02-07 23:29:5518656125ea784a55b38328f01cb4699b50d1548d701730c9ca3e938c4e9d8e54dll RecordBreaker
2023-02-06 22:07:11b06c5fb7651b8a6c683b62babcabd18da4d992f7d1e0f963c530832b18feacf4dllRecordBreaker
2023-02-06 13:19:04887d6ad4cffeedfd403427c94439bcb265e54d86e0166956bb978cfa24c55c27dllRaccoonStealer