URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 20.226.26.143
Firstseen:2026-01-26 16:27:04 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-26 16:27:07 20.226.26.143Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- BRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-26 16:27:07http://20.226.26.143/02.08.2022.exeOfflinecensys CobaltStrike ext DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-26 23:57:3599b52eac82c4c4fca2a83d8c2fb4327df7331c9064e60a95d2e55108e874a205unknown  
2026-01-26 16:27:07637260109a727303290323f6354c22fe65aab8b25293d36ed7e66069efa703b6unknown