URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 37.46.150.92
Firstseen:2021-02-11 07:53:02 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-02-16 00:32:04http://37.46.150.92/notabotnet/notabotnet.arm7Offlineelf tolisec
2021-02-16 00:32:04http://37.46.150.92/notabotnet/notabotnet.armOfflineelf tolisec
2021-02-11 07:54:09http://37.46.150.92/update2.exeOfflinebitrat ext exe opendir abuse_ch
2021-02-11 07:54:03http://37.46.150.92/IMG_5723.xlsOfflineopendir xls abuse_ch
2021-02-11 07:54:03http://37.46.150.92/IMG_2752.docxOfflinedocx opendir abuse_ch
2021-02-11 07:53:06http://37.46.150.92/update.exeOfflinebitrat ext exe opendir rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-02-16 00:32:04251016c3e0c0956676544ebe8f42ae754e6679fbc53482ec4e15cf54c75f7c7delf  
2021-02-16 00:32:04f46a5dc812e81ea251dfad3d20418b1b732d8cc82ba2da2881e01eaa0111b881elf  
2021-02-11 07:54:096c2a2251861a6d2701814843fadac940cf4d34db9f446f0698352fd866b31739exeBitRAT
2021-02-11 07:54:03f3ffc668b39a455b981aa7866e87d7a4af8bcb1899ab7e3b6ef7a9191be0ebbdxls 
2021-02-11 07:54:03384d5efae92a932e2b526e2cd44e8d7ed57e5ccc78f82912ac500f3bb61ed80aunknown  
2021-02-11 07:53:06735b19cc36976e7d8bce35a68558b35224ce32168ccdf92979b5d4a795ae76bdexeBitRAT