URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 205.185.122.246
Firstseen:2020-05-13 14:27:02 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-13 14:27:07 205.185.122.246Not listedAS53667 PONYNET- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-06-10 05:51:03http://205.185.122.246/files/june9.dllOfflinedll ZLoader ext abuse_ch
2020-05-13 14:27:07http://205.185.122.246/files/may13.binOfflineParallax ext ParallaxRAT ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-06-10 11:37:16c653365657fbf65429ad845d0a0d93106e972aca929739560ff4b4796bd2be08exeZLoader
2020-06-10 05:51:030829886e0ca34a32fa545e0a53d7a2208d963b7b826a14aefde94d9ff4f549e5exe 
2020-05-13 16:01:1576c2929d5ccb9232c3e3b9825bbde0f7fb135a1cdc035297322212b48f1b91c3exeParallaxRAT
2020-05-13 14:27:062ae1c7a5828344b803f6c5085ff52866be49fc5ec3c3e868d850283a6e8fce59exeParallaxRAT