URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 213.209.150.113
Firstseen:2025-08-20 12:10:06 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-20 12:10:12 213.209.150.113Not listedAS2856 BT-UK-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-20 16:12:08http://213.209.150.113/files/341953163/1gbaAn2.batOfflinec2-monitor-auto DarkVisionRAT dropped-by-amadey c2hunter
2025-08-20 15:12:11http://213.209.150.113/files/7596020081/AUjCn3t...Offlinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 15:11:12http://213.209.150.113/files/801193963/114wZ2y.exeOfflineAmadey c2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 13:24:10http://213.209.150.113/files/8042875554/6Rc9W1x...Offlinec2-monitor-auto dropped-by-amadey QuasarRAT ext c2hunter
2025-08-20 13:17:07http://213.209.150.113/files/7127454373/Zxr2QtI...Offlinec2-monitor-auto Chaos dropped-by-amadey c2hunter
2025-08-20 12:32:26http://213.209.150.113/files/1229664666/8ihVFH8...Offlinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 12:32:24http://213.209.150.113/files/7767269296/hpPbN0Z...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:23http://213.209.150.113/files/7125646839/i0q3uva...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:22http://213.209.150.113/files/1509384686/NW1JmQQ...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:17http://213.209.150.113/files/7886909490/z8ot0Fy...Offlinec2-monitor-auto dropped-by-amadey Stealc c2hunter
2025-08-20 12:32:17http://213.209.150.113/files/6331503294/wIiwRJJ...Offlinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 12:32:15http://213.209.150.113/files/271085713/Y3WxsSs.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 12:32:15http://213.209.150.113/files/5296057416/Tse2E3k...Offlinec2-monitor-auto dropped-by-amadey Stealc c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/740061926/bLGj4G0.exeOfflinec2-monitor-auto dropped-by-amadey gcleaner ext c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/7453936223/RenT7Wg...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/5638395652/yhxBBcU...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/7610129705/jh8ta1W...Offlinec2-monitor-auto dropped-by-amadey RedLineStealer ext c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/5254702106/trvb3cO...Offlinec2-monitor-auto dropped-by-amadey Stealc c2hunter
2025-08-20 12:32:13http://213.209.150.113/files/1509384686/SJovRNE...Offlinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:32:12http://213.209.150.113/files/6361558956/qwcFbW4...Offlinec2-monitor-auto dropped-by-amadey N-W0rm c2hunter
2025-08-20 12:32:12http://213.209.150.113/files/8434554557/M6XCVER...Offlinec2-monitor-auto dropped-by-amadey PureLogsStealer c2hunter
2025-08-20 12:10:23http://213.209.150.113/files/unique2/random.exeOfflinec2-monitor-auto dropped-by-amadey gcleaner ext c2hunter
2025-08-20 12:10:18http://213.209.150.113/files/7596020081/E5pj38A...Offlinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-20 12:10:12http://213.209.150.113/files/fate/random.exeOfflinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter
2025-08-20 12:10:12http://213.209.150.113/luma/random.exeOfflinec2-monitor-auto dropped-by-amadey LummaStealer c2hunter

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-20 19:05:051baebf4eace8dda9bfa0acc7516b4633712fdefa92f0563ef99084c5c75e74cfexeGCleaner
2025-08-20 16:12:08c84cf393fe6d5c8157a4d899a2a658ad2e95df67891d77108ab3be5ce7e01f9bbatDarkVisionRAT
2025-08-20 15:12:11040570be620da2c9a902e03b11de64c75d85ffd37ee6ae1d504e6144d6ade483exe 
2025-08-20 15:11:11c1fcdbc77e5ab2ebfbf3bd0adc2d81bd64ed2dfdacccfea9783003cf950ac36bexeAmadey
2025-08-20 14:28:0004651b5ea2f5abd76dfffd4630d54ca23bf2a3c30f53e4ccc213f0f669b7e834exeGCleaner
2025-08-20 13:57:3396024042d0dea1ab62db489fba07834dced65fe1e2d09b33ccdc41c388d11609exeLummaStealer
2025-08-20 13:24:10d77857e39d36842225e58a9d5977d73c86e5158858225a92ec16b2f2ca522fe3batQuasarRAT
2025-08-20 13:17:0712e3e2892fe31aab9eec0986e106cf2c0ad1fa9fe162dcd2cd7eb1ef3327e96cexeRansomware.Chaos
2025-08-20 12:32:25cf0e7668679342b05b807f28784c101a1b95b0a314ffdf4e8ab426a77e573d83exe 
2025-08-20 12:32:24a76bf1e070fc6280d698e8a413c0d258df4ad2024525896700a138b51cba20ccexeLummaStealer
2025-08-20 12:32:234a6f6df6942d41b1e9ae60a661ea7fb828563638dedf57af3c26720d99c49ed1exeLummaStealer
2025-08-20 12:32:22aca862498dc80512772af2d41368322b102d3d34fbb7538436ec8881b17c217dexeLummaStealer
2025-08-20 12:32:17b614be79d0c6b529345bf056ca1201bc1ffdba0d85677c648297a993706b5498exeStealc
2025-08-20 12:32:162dbe6dcda7e8c51276da7c5635cd52fb044cfb2278b7d3c3f045d4037249245eexe 
2025-08-20 12:32:15adfb54bc178bd596a6d011a2dcd782cffe3e7bb37cbd07d1ac5daaaf307094ffexeStealc
2025-08-20 12:32:13353bb7ff551cc81d11dd41b3ac03084ab2ce72a86099a6010a9ac5d6a67cc5d0exe GCleaner
2025-08-20 12:32:1392f4fdda0cd9f0b734c3f68cec7e7cf72dd0e2ee740c63eca63ddbb560f2ed53exe 
2025-08-20 12:32:132371b0a66328458ddff16721811d686dff6e689139a21ef76bd67e2b7e291e25exeLummaStealer
2025-08-20 12:32:13e15886e3c6af9edae546b18f8cce879de2773538cebd598748af924db890da40exeLummaStealer
2025-08-20 12:32:13e12ee7f81b36119f286b0aef02de51905a17c14433a37439f089e07baf3044ceexeRedLineStealer
2025-08-20 12:32:138441f8b903c676d468bb0b0c07d699cb98df153cc50b4ac566e7ab95293cd2dbexe Stealc
2025-08-20 12:32:12aca862498dc80512772af2d41368322b102d3d34fbb7538436ec8881b17c217dexeLummaStealer
2025-08-20 12:32:12765bd0d1ba46da4d04c560ecdac0c0a1b8ab1dc9fd3665de59bced81cdb43712exeN-W0rm
2025-08-20 12:32:12eb49eee9fa02595b47f911c3148fa04d53cd72e11ff88e86f6e868e795a8bfcaexePureLogsStealer
2025-08-20 12:10:23050f2713c672fef785c006ad7243e5ed913fa5a396cb2739f0ceaf1ddadadaa0exeGCleaner
2025-08-20 12:10:1144ae36e347284bf332e319d0dfff30bcd0ebcfa1eec1ae5741f32464bd2e5cc0exe LummaStealer
2025-08-20 12:10:09099250469c23007b02b117b43e6a1b29d24944eebb4c12b0cdc553556d414ca8exeLummaStealer