URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 46.183.223.121
Firstseen:2023-10-02 16:23:03 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-10-02 16:23:05 46.183.223.121ip-223-121.dataclub.infoNot listedAS52048 RixHost- LVyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-10-02 16:23:05http://46.183.223.121/ansi/loki.exeOfflineexe Loki ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-10-04 01:47:22da5c8721b3c8624f2234309272d145894cbb0242281c5bd7cfa9e804842fc6e2exe Loki
2023-10-03 22:58:49af0b630ad64ed3f1b91f55389e78fe82c2b0dcaee4965b6442ec2c6814a38da5exe Loki
2023-10-02 23:18:52d581e18227b09069cce82bcb38f8bc2706ce37400e23ab173a903c4b01804275exeLoki
2023-10-02 16:23:04b8f3640dea3f2e076ea541cc764cef60ac8cdf9f25f01e728ae68dced5d04714exeLoki