URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 57.131.18.205
Firstseen:2026-02-13 20:01:03 UTC
Total malware sites :6
Online malware sites :5 (83%)
Offline Malware sites :1 (17%)
Newest active malware site :2026-02-13 20:01:05 UTC
Oldest active malware site :2026-02-13 20:01:05 UTC (Age: 15 days, 10 hours, 50 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-13 20:01:04 57.131.18.205Not listedAS16276 OVH- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-13 20:01:05http://57.131.18.205:8085/via.wshOnlineopendir WsgiDAV DaveLikesMalwre
2026-02-13 20:01:05http://57.131.18.205:8085/tpol.batOnlineopendir WsgiDAV DaveLikesMalwre
2026-02-13 20:01:05http://57.131.18.205:8085/rechung/Mahnung-SKM99...Onlineopendir WsgiDAV DaveLikesMalwre
2026-02-13 20:01:05http://57.131.18.205:8085/xe.zipOnlineopendir WsgiDAV DaveLikesMalwre
2026-02-13 20:01:05http://57.131.18.205:8085/sar.jsOnlineopendir WsgiDAV DaveLikesMalwre
2026-02-13 20:01:04http://57.131.18.205:8085/sana.batOfflineopendir WsgiDAV DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-13 20:01:050c27cc462881cb0b6ff016ddaea39eb1748e524356b1f5b7bd8f96e7e3958e86unknown  
2026-02-13 20:01:056ef6e766538e086d601aca90cbfa510cb225cfc5b64ef879a66b256118bce2eebat  
2026-02-13 20:01:05573651145b526a198f3329dff814be9a798924426e7f0abb0960b2e6bba3c4felnk  
2026-02-13 20:01:05bf822403a21982d36ea735f4123a8fa82c52454ce688b4faecd1cc1f67c20b1czip  
2026-02-13 20:01:050008e5302615cc7ddccb1d271a5d18b568d9fa691feadd02faaf0ad0cc9fbc63js