URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 52.161.2.12
Firstseen:2022-02-14 07:51:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-14 07:51:05 52.161.2.12Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-25 06:02:06http://52.161.2.12/rmr/photos.exeOfflineAveMariaRAT ext exe opendir rat abuse_ch
2022-02-24 16:59:06http://52.161.2.12/tws/coco2war.exeOfflineAveMariaRAT ext exe abuse_ch
2022-02-24 16:59:06http://52.161.2.12/ecx/coco1xl.exeOfflineexe Formbook ext opendir abuse_ch
2022-02-14 07:51:05http://52.161.2.12/ru/image001.exeOfflineAveMariaRAT ext exe opendir rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-25 06:02:06291e48a84fe8aa0fd59df0a786b8a61c5f57a8850cc620afdf3873487f4704d0exeAveMariaRAT
2022-02-24 16:59:06a7f53b92008e8a3678035fc366bc1b88d152efc8466e9e82c754752d000a5ad5exe 
2022-02-24 16:59:067146b418cdd99ac478a67e603bffb10c10f1c32745da1fd60c931f54f1f114a6exe 
2022-02-14 07:51:054abee8ed31d31112c7338025f2bd96f0d6232a36db9711e6e45ee9e7f1f9c461exeAveMariaRAT