URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 212.11.64.143
Firstseen:2026-02-13 16:46:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-13 16:46:06 212.11.64.143SBL678087AS42624 swissnetwork02- SCyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-17 17:24:14http://212.11.64.143/Documents/WF_eStatement_02...Offlinegorat lnk xml-opendir DaveLikesMalwre
2026-02-13 16:46:06http://212.11.64.143/Documents/statement.zipOfflinexml-opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-17 17:24:14a6a37341db0b3747abc3c8a116fb59520372f6ee39c00191432988f12c9735cflnkGORAT
2026-02-13 16:46:065cdb12a85ef7529ee4cff7fbf2d88e100b9ad4428499f3656c9102ee10271803zip