URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 34.159.167.20
Firstseen:2023-03-16 15:51:03 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-16 15:51:13 34.159.167.2020.167.159.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-16 15:51:13http://34.159.167.20/Bpznb.msiOfflineLaplasClipper Stealc crep1x

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-17 12:57:5923f0440bae78c2d40ebdf75a4127857fd531ea167e7525271330e966e24fa13amsiStealc
2023-03-16 15:51:07015151bd2d2bfb88389899bfac44b0e17a28db00abc8e1463058d84de40b1925msiLaplasClipper