URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 198.46.132.132
Firstseen:2021-02-22 13:22:02 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-02-22 13:22:04 198.46.132.132198-46-132-132-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-04-13 06:00:05http://198.46.132.132/new.exeOfflineexe Formbook ext abuse_ch
2021-04-08 06:25:05http://198.46.132.132/file.exeOfflineexe Formbook ext abuse_ch
2021-03-25 09:16:05http://198.46.132.132/local.exeOfflineexe Formbook ext abuse_ch
2021-03-17 17:55:06http://198.46.132.132/ooo.exeOfflineAgentTesla ext info_sec_ca
2021-03-14 17:09:05http://198.46.132.132/razi.exeOfflineAgentTesla ext exe abuse_ch
2021-03-04 15:09:05http://198.46.132.132/doc/ami.exeOfflineAgentTesla ext exe gorimpthon
2021-03-03 13:52:05http://198.46.132.132/doc/sativa.exeOfflineAgentTesla ext exe gorimpthon
2021-03-01 19:05:05http://198.46.132.132/Benz.exeOfflineAgentTesla ext exe abuse_ch
2021-02-22 13:22:04http://198.46.132.132/ali.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-13 06:00:05e07b53897e282a020b5f62e4ae4b78b0517e7cf5797ceb7ecf8ef90a52fff6e2exeFormbook
2021-04-08 09:55:51d234c88f0c47386bc8960ff667f0fe2d42bfc8a2f1ffcfea401f875ee3c5b23bexeFormbook
2021-04-08 06:25:05da51c0642c1d22815991ec7f4da9f27206352ee2c5419d29af09cb69688b0b47exeFormbook
2021-03-31 22:30:14bfd74e1ea55e63ca7d7b298355a632f8df0f3fc558ae721ef21cc60ae08b82bbexeFormbook
2021-03-31 12:13:047a4de78c5eed937a8aa4e3149fac38d38fd0275ddc45b2a481f266c421230e5dexeFormbook
2021-03-30 21:50:48f7dc24b214db050895707a8e89d730f2230d3b235eb5d19b65807139a82c49b1exeFormbook
2021-03-25 09:16:0517e606baa0797fd83464d43902b1705226c1d03522dbf5aa9077fe6ef1ca55c6exeFormbook
2021-03-17 17:55:0602fd540169425f4f71bab994c4f1faf127f56a272e8dfb547fa0e74375bab6a6exeAgentTesla
2021-03-15 00:16:25cf0f9462ba658c843a0487fc3480a46395d317808b190ce54167a0a8e2ded7a0exeAgentTesla
2021-03-14 22:49:56b2ae47f62aa239fb6badfb8af83054c008e9c93d6fe1953732ec03029dc474ceexeAgentTesla
2021-03-14 22:29:394126380b3ee04197336d8f6a48384ec73289e4fa14762bec745089f4699b2330exeAgentTesla
2021-03-14 17:09:054b9c39b0624ed5da7d8ffeb5b8de89562a0ba2db40e4899160fdd1e51efa63eaexeAgentTesla
2021-03-04 15:09:05d62db8a909debd7ac39dca5850db5bf150756f27cc50417efc285a812b378b84exeAgentTesla
2021-03-03 13:52:05d3b364b24f73d49e47de066a72532ddb9d00489286c8cc53e104d4ae9a1b8bbfexeAgentTesla
2021-03-01 19:05:05a51664afbc2829874c85882cffcabccb4540b08a6c1ed78a7284e6312b673d07exeAgentTesla
2021-02-22 15:55:3130e4bee5bf128236c294ca4c6a6218ed812ae24eef0749356a86ca499a260713exeAgentTesla
2021-02-22 13:22:04bca848afaa837ef13fb109759901d9308ed1af12db6fbdd55ad8f4ee857c6857exeAgentTesla