URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 198.23.212.140
Firstseen:2020-11-11 09:31:02 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-11-11 09:31:05 198.23.212.140198-23-212-140-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-13 16:10:57http://198.23.212.140:63006/VreOfflinevjw0rm Cryptolaemus1
2020-11-12 07:42:05http://198.23.212.140/doc/cash.exeOfflineexe oppimaniac
2020-11-12 07:42:04http://198.23.212.140/doc/frankf.exeOfflineexe oppimaniac
2020-11-11 09:31:05http://198.23.212.140/doc/ohms.exeOfflineAgentTesla ext exe oppimaniac
2020-11-11 09:31:05http://198.23.212.140/doc/xyy.exeOfflineAgentTesla ext exe oppimaniac

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-11-12 07:42:0505163042425da44fed5691a5490563f89a415577452a355397ed27d3ba1323d7exe 
2020-11-12 07:42:044850c6f42a75ecff416b68fb39f7bd261527065704b35f24328b7055995cf27dexe 
2020-11-11 09:31:057543d16d9eb66ebcb61a632b705609940389665e09e7e4bdc3ec33f3612d1dcbexeAgentTesla
2020-11-11 09:31:05a3230e59a4a3a5f499ff5d3f6a6d595ba1be76befacea3a3770d9980298d4583exeAgentTesla