URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 20.106.125.237 |
|---|---|
| Firstseen: | 2022-03-01 08:44:03 UTC |
| Total malware sites : | 5 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 5 (100%) |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-03-01 08:44:06 | 20.106.125.237 | Not listed | AS8075 MICROSOFT-CORP-MSN-AS-BLOCK | US | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-03-01 08:46:06 | http://20.106.125.237/less/cocxl.exe | Offline | exe Formbook | |
| 2022-03-01 08:46:05 | http://20.106.125.237/image/images.exe | Offline | AveMariaRAT | |
| 2022-03-01 08:45:06 | http://20.106.125.237/ups/bups.exe | Offline | AveMariaRAT | |
| 2022-03-01 08:45:05 | http://20.106.125.237/yakfileloadsonedrivedocum... | Offline | AveMariaRAT | |
| 2022-03-01 08:44:06 | http://20.106.125.237/co/cowarz.exe | Offline | AveMariaRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-03-01 08:46:06 | 6d3ef9ddf5f1d57d353e5d8b9bedbca6ab42765de06abf381534126d24142948 | exe | Formbook | |
| 2022-03-01 08:46:05 | 2919072310f5582f6a311b123a3e1f6c13a5f2a0b8f1df8a4ef58081bdb42781 | exe | AveMariaRAT | |
| 2022-03-01 08:45:06 | 1177106451286cd9bd71b3abf162e30f6a37a3ca09f392421fda990412211349 | exe | AveMariaRAT | |
| 2022-03-01 08:45:05 | b08ee21f9ec7e5883fbb53b567995617a449affd4e17cd71b310eafd8728fc4b | unknown | ||
| 2022-03-01 08:44:05 | f1dd77df504fc9a38076b58b80cb2b7c80d018aba6d762ec758b76afd62952cc | exe | ModiLoader |
US