URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5.189.161.33
Firstseen:2025-09-05 06:12:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-05 06:12:08 5.189.161.33vmi2774342.contaboserver.netNot listedAS51167 CONTABO- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-09-05 06:13:06http://5.189.161.33/data/01.zipOffline s1dhy
2025-09-05 06:12:18http://5.189.161.33/data/setup.exeOfflineStealc s1dhy
2025-09-05 06:12:10http://5.189.161.33/data/data.exeOffline s1dhy
2025-09-05 06:12:08http://5.189.161.33/data/go1.zipOffline s1dhy

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-09-05 06:13:067e8b69b37cd9f7c0cec4df1d39d1434737124111c227f25d4422544a1a0bc8f4zip  
2025-09-05 06:12:17a81e17ccf971da0699a08df991d99b433aed6431b660b2010cfc6e41288c8abeexeStealc
2025-09-05 06:12:102d55dd55ed7bc12e9eeb1ef36035e05c8bc41c45b01af0fbc57a366d27834e2bexe 
2025-09-05 06:12:083040d520ec41f9f695c286069e7be61c27e7cc2c497f1b6046b96c39ddf4a2ebzip