URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5.206.224.216
Firstseen:2020-05-07 21:57:02 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-07 21:57:03 5.206.224.216libraryNot listedAS47674 NETSOLUTIONS- PTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-05-08 07:33:04http://5.206.224.216/private/water1.binOfflineencrypted GuLoader ext abuse_ch
2020-05-08 04:42:09http://5.206.224.216/imp/declarations.csvOfflinezip zbetcheckin
2020-05-07 21:57:03http://5.206.224.216/private/tmp.exeOfflineFormbook ext JayTHL

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-05-08 07:33:04b469d3f27e2020ccfff98c4308d61f0d0fc22acad6012f19b15e436020d8b1c9unknown 
2020-05-08 04:42:09e5d50ba3a4bbe46af9327ee03eb229f2074c6f93a65764aedf08670ab7b62ec0unknown  
2020-05-08 02:13:08cbe345880baebbc56c019721184c56577bccf0b66091b09f90163646f0bc7af7exeFormBook
2020-05-07 21:57:038502092cc063df88e152df2357b9a1854a669168705effd830304055092b5ca7exeFormBook