URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.87.163
Firstseen:2025-08-26 05:24:05 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-26 05:24:29http://196.251.87.163/downloadOfflineexe GenesisStealer burger

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-09-03 02:39:09c6f837510557f1630ad2c415ba0670e73dfd50daa65379a2d941dbfd248f2738exe  
2025-09-01 20:30:48723e1087a0091ef040dd5b74fb59362dd78895a32451e0e0e1d9d1081060bb04exe  
2025-08-28 20:00:097d376db594d7e8a305209dc7ff75a0cfa368d4991a6e8c1da639e10426797362exe  
2025-08-26 19:42:016812094fa5eb02d7835e91b8f056dcb73a018ff4182637ff6f957ea6f06209ddexe  
2025-08-26 05:24:2950a362c59eac4bd2d6c3e211f3cdd661653f49d5050806f698949c7211ac6a7bexeGenesisStealer