URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 2.58.149.200
Firstseen:2022-03-22 16:26:03 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-22 16:26:33 2.58.149.200Not listedAS212238 CDNEXT- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-06-24 05:42:04http://2.58.149.200/somx.exeOfflineexe Loki ext abuse_ch
2022-06-23 10:32:04http://2.58.149.200/evalax.exeOffline32 AveMariaRAT ext exe zbetcheckin
2022-06-22 22:13:03http://2.58.149.200/venta0.exeOffline32 exe SnakeKeylogger ext zbetcheckin
2022-06-17 13:53:03http://2.58.149.200/32/mbo.exeOffline c_APT_ure
2022-06-14 08:06:03http://2.58.149.200/bdel.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-13 21:44:05http://2.58.149.200/nedx.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-13 20:13:04http://2.58.149.200/mbo.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-13 08:54:04http://2.58.149.200/explot/mob/mobd.exeOffline c_APT_ure
2022-06-13 08:54:03http://2.58.149.200/explot/doc/docv.exeOffline c_APT_ure
2022-06-09 07:54:04http://2.58.149.200/nedsx.exeOfflineexe SnakeKeylogger ext abuse_ch
2022-06-09 07:53:03http://2.58.149.200/sNop.exeOfflineAveMariaRAT ext exe rat SnakeKeylogger ext abuse_ch
2022-06-09 07:53:03http://2.58.149.200/rcwpQWE1.exeOfflineAveMariaRAT ext exe rat abuse_ch
2022-05-26 02:13:04http://2.58.149.200/Lifeleaf2.exeOffline32 exe GuLoader ext zbetcheckin
2022-05-24 23:27:03http://2.58.149.200/explot/gob/gavac.exeOffline32 exe Loki ext zbetcheckin
2022-05-24 19:49:04http://2.58.149.200/explot/ab/abl.exeOffline32 exe Loki ext zbetcheckin
2022-05-24 18:56:04http://2.58.149.200/explot/ebguy/ebug.exeOfflineexe Loki ext opendir abuse_ch
2022-05-01 04:26:03http://2.58.149.200/explot/agu/agu.exeOfflineLoki ext lokibot ext pr0xylife
2022-04-28 06:59:04http://2.58.149.200/explot/mob/mebx.exeOfflineexe Loki ext abuse_ch
2022-04-28 06:59:04http://2.58.149.200/explot/ned/nedx.exeOfflineexe Loki ext abuse_ch
2022-04-12 12:02:04http://2.58.149.200/explot/ebguy/sanx.exeOfflineexe Loki ext opendir abuse_ch
2022-03-23 09:54:03http://2.58.149.200/explot/ned/nd.exeOfflineAgentTesla ext exe abuse_ch
2022-03-22 16:26:33http://2.58.149.200/explot/mob/mob.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-06 07:41:59f3d286d8a5034375b26d246fbe6c52ae805168a6a5a9fe64e8354ad0886d0e11exeAgentTesla
2022-07-05 17:40:051b4be95bfee9339ccccf401c3f20090a9945bbd80c6ba480315db116cb46b6ddexe AgentTesla
2022-06-24 05:42:04e99f0195f624b2fa3304e3449916bb65bbcba86838a23020bd49cefa1b10065dexeLoki
2022-06-23 10:32:040e4ad18e1078eccf7911e552ca943984c583c1efe7fa4672dbaa9ee6fc759424exeAveMariaRAT
2022-06-22 22:13:03b3c1d0252adba6ec3d9209c8e79e934ae8a43d3b8f6bc1e1f29df40d6fedf04eexeSnakeKeylogger
2022-06-14 08:06:035b960ec264664c624798db69996efaee5a732557ee3ac8f6b9717233e073c0afexeAgentTesla
2022-06-13 21:44:055115d6bc2463203dc0ec2fcda3ca9a3c4e17892d6c79053d9c748cd752966a31exeAgentTesla
2022-06-13 20:13:04a0ccc4fe9ce9e08e5cba330fdb9e824c4712b9388c035e2caac957d64580db37exeAgentTesla
2022-06-09 07:54:04f28ffd61c5a3328550372b96d415ec112a6065c88821a519b50c4355df80a346exeSnakeKeylogger
2022-06-09 07:53:0308bbf746d956d22bbb5068c212f3e743538d20e51d7bc14b075361cd4eadaa5dexeSnakeKeylogger
2022-06-09 07:53:0387d3f9671d02f12f33c3856593bd3568b0b1932e5b263fc9035f8006f1b23d7bexeAveMariaRAT
2022-05-26 02:13:041be03967a615254ca0b3eba8b5aaa6b5f5c91c9f03d4fe2692b3675f93c0b26dexeGuLoader
2022-05-24 23:27:03733fe12344bc6e3ee3220031671c15d312007ff1d664a8f54ba7d98cbf0610efexeLoki
2022-05-24 19:49:0451fcaaed0a9b1ed4b45d70828527990da0b6dd7f17938383e0cbd931376702a0exeLoki
2022-05-24 18:56:03f0d331eae40b27d0c64cbaea0e09e423f5872fbdef8b36e7cf4ea4295ca47acfexeLoki
2022-05-01 04:26:0387bfad2cfa3d233cd6e5ee781bde7ffd9355131993ea1bb3f9412e58125c8ea9exeLoki
2022-04-29 08:23:4134233068e267ac561ccd8ee82c42d87f572ab92c6d54c48d35c2d6e87a90c3bdexe Loki
2022-04-28 06:59:0492896afd836208b63ec1d1e850a5b5278de069772f3dc638de35cdc69aa9102cexeLoki
2022-04-28 06:59:04e891522137cc5ea74e8c3576cdc3a8a8114ca4bc379b7c7b48896d3e5d553b31exeLoki
2022-04-12 12:02:045833bb5b323155bc7055ccec5ce39e093901b609ccde004f104857abca656c3aexeLoki
2022-03-24 10:05:43ee6901e9c2d103989b74a55d91b9cf734b19a177daf8f8561e0d805bf5544e6eexeAgentTesla
2022-03-24 09:51:410d1a7b5c97ef2fd1275597ba27759208cb2540b4675837a14c86bef5d4effa1cexeAgentTesla
2022-03-23 09:54:03e8113cb73f2c87ceece965da48e6f55a222fa92c6800c069babe30dfd76db633exeAgentTesla
2022-03-22 16:48:288e655c6ae80c8d8ea8c4adc15ac7aded61dac1126faa674a0ef1665df616bc9fexeAgentTesla