URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.107.94
Firstseen:2025-11-20 07:09:05 UTC
Total malware sites :5
Online malware sites :4 (80%)
Offline Malware sites :1 (20%)
Newest active malware site :2025-11-20 07:09:17 UTC
Oldest active malware site :2025-11-20 07:09:07 UTC (Age: 2 days, 8 hours, 54 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-20 07:09:05 196.251.107.94SBL678968AS214351 FEMOIT- DEyes

Malware URLs


The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-20 07:09:1723c9f46f71159e646579cfb1327393cae34ac66bac183831852d7121beba935aunknown  
2025-11-20 07:09:087bd1a323e9a3b32c257589cd85abe3064d97dadb3cbc24096a7e946e79a22df1exeDonutLoader
2025-11-20 07:09:07fb790e2db7ebb409abb155124f071c94f9e9275f17f277ca842d1bf9bded4940exeDonutLoader
2025-11-20 07:09:078f258a2c054422d6c511062fed1a48842d6aa4030adb7ccd61dabd4cb0a1e048unknown