URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5.2.75.46
Firstseen:2021-12-29 23:34:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-29 23:34:04 5.2.75.46Not listedAS60404 Liteserver- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-30 05:54:04http://5.2.75.46/myforum/images/380.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-12-29 23:34:04http://5.2.75.46/myforum/images/378.exeOfflineCoinMiner exe zbetcheckin
2021-12-29 23:34:04http://5.2.75.46/myforum/images/377.exeOfflineexe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-30 05:54:049e1565a4e0af404cf7eb096a60ddb70b5d5adf849312ea6f76c6374841759166exeRedLineStealer
2021-12-29 23:34:04b82563ef051fd4c829aae24747f4f68c20d759a1535c0456e2e93659bb512cf8exe 
2021-12-29 23:34:03d9b6982e6ebb44f281207474f885164df5748889ee12d2f21ceaf13ce1315f52exeCoinMiner