URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 50.16.4.125
Firstseen:2022-01-25 10:20:04 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-25 10:20:06 50.16.4.125ec2-50-16-4-125.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-25 10:20:06http://50.16.4.125/E/raki.exeOfflineexe GuLoader ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-27 06:19:00e2ccd7e2fcd967ecf2897e5e07601af5387be751e0f6551ecd969239c2e69206exe  
2022-01-26 04:36:104468c48f99c92e56bb04921a42676511c64b39f9ae99fcd08f2a10251618baf2exe  
2022-01-25 20:51:17705340607567673194acd70da2bf31d50671d4813e9382e723cdaab52d02a540exe  
2022-01-25 14:35:0027991598dd6658e0d207b7ad90c741ae37fe1ea6313885547132160691848a07exe  
2022-01-25 12:49:37c2bc3785322d6d782c6e6ef18d7a6e310e3ad03cb6878787c28b94f46f6a754bexe  
2022-01-25 10:20:054f29b22b6b787babc2f984172f8ae0e3999b7621aeb6775ce023f2ef5db0b2e7exeGuLoader