URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 37.139.129.113
Firstseen:2022-11-01 06:07:04 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-01 06:07:04 37.139.129.113Not listedAS210218 OpenFiber-Italy- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-11-01 06:07:09http://37.139.129.113/wow/1/2/3/4/5/6/7/SmartDe...OfflineCoinMiner CoinMiner.XMRig exe tcains1
2022-11-01 06:07:06http://37.139.129.113/wow/1/2/3/4/5/6/7/SysApp.exeOfflineexe tcains1
2022-11-01 06:07:04http://37.139.129.113/wow/1/2/3/4/5/6/7/new2.exeOfflineAuroraStealer exe RedLineStealer ext tcains1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-04-06 13:39:214a7550dd00289e694500a2c3aef27b903136ee4a99f25e48fc75be2c68ae0e48exe CoinMiner
2023-04-04 06:50:09e9650732978b458f756d090c3fed9e70b6c82510a2438c3dbf7f34aa88fa3254exe  
2023-03-16 01:23:353827b2d39eb48088817b350a6a2ed9b1de9c1a4d5f33bfab0bec1ecff99aeb45exe  
2023-02-12 18:07:060a6ed49a01a7c4cad6ea914495d5789b97a9993508fe82ff3232613afb2a0789exeAuroraStealer
2023-01-29 08:52:10f0cc93428ff55575086b843e642c33283067a980fc9cb1f17afc3559b101ff1bexe RedLineStealer
2023-01-21 23:54:060f1d090c622967acfa7bde2ef5238255ce8924d5ff7bbf72661821e3d901f299exe RedLineStealer
2023-01-15 22:57:47ac9057fdc650c801c3120613a20e0b03ce5a9c89708ef4a7026bd30df71c5ffdexe 
2023-01-15 22:45:21d80ce10659442d8e5b9c28e53bf254711881cf9502f52aeb8abf4a15c9e6e36eexe RedLineStealer
2022-12-07 13:27:33b9bfdd7d9a090da9ceaf2d4df414e8fd212a048692b5d90cec81d4e1b1918679exe RedLineStealer
2022-11-19 18:02:57ea42fcee681ec3b06dac54d3da4b866143d68cbaa0dd0e00e7c10ae2a7c9d2aaexe  
2022-11-15 11:05:38fbc2c0e4cd92c2baf24a96418c5598cc62bf11171e1bb7c423332c3f6782f37bexeRedLineStealer
2022-11-11 12:58:32a6ab90d5445d7ff822f3d9401ab6c438e624d416575d68be8eb4336f3c41c9ddexe RedLineStealer
2022-11-02 17:14:51d6516a119c2c08859883d95f97b0bd4b2fb8fbad7d7fae6ed2d79b447177d408exeCoinMiner
2022-11-02 13:38:345d5e9a03a29d4e638a175b889a5bb73fbcb0809ac83aa6966324fe86ac408d17exe RedLineStealer
2022-11-02 09:06:549dedf6026296be04ac67e92ffee045c61bac60094bebce1b158fc6cea6f53fa0exe RedLineStealer
2022-11-01 06:07:095d9d30f4a9e254cd3754c47ca59ac4d4e0f50f4d6fd6564e777819d1701be81eexeCoinMiner.XMRig
2022-11-01 06:07:06dd47342f809e86e447b68827dd3a1e72ea0795b71976ecd6fa242013b767b14fexe 
2022-11-01 06:07:04902426c4cd2fb4673caaff25004dfdb3d34609e51c458aab621ca655da376728exeRedLineStealer