URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 62.204.41.121
Firstseen:2023-01-18 08:36:03 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-01-21 03:22:04http://62.204.41.121/lend/HouseGC.exeOffline32 exe RedLineStealer ext zbetcheckin
2023-01-21 03:05:05http://62.204.41.121/lend/Marauded.exeOffline32 exe RedLineStealer ext zbetcheckin
2023-01-20 02:29:04http://62.204.41.121/lend/tube.exeOffline32 exe zbetcheckin
2023-01-19 12:31:04http://62.204.41.121/lend/bhada.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-19 12:30:06http://62.204.41.121/lend/winrar.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-19 12:29:04http://62.204.41.121/legion.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-19 07:47:05http://62.204.41.121/lend/fe.exeOffline32 exe zbetcheckin
2023-01-19 07:46:05http://62.204.41.121/lend/Speedy.exeOfflineDarkTortilla exe zbetcheckin
2023-01-18 08:36:14http://62.204.41.121/lend/buildppb.exeOfflineAuroraStealer exe abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/NATEppp.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/ztf9phdgi2oi7q.exeOfflineexe RecordBreaker ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/huf6dcojjmd.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/V6ieHw0lKtnWpzU.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/tcg05w40u9.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/qiv1ow16wzuw.exeOfflineeternitystealer ext exe abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/9mbpbo6qiofdjh.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/AntiVirus.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:12http://62.204.41.121/ZxhssZx/Plugins/cred64.dllOfflineAmadey dll abuse_ch
2023-01-18 08:36:12http://62.204.41.121/lend/msve.exeOfflineexe xworm abuse_ch
2023-01-18 08:36:11http://62.204.41.121/lend/3eaxk3ch1hxkih.exeOfflineexe RedLineStealer ext abuse_ch
2023-01-18 08:36:10http://62.204.41.121/ZxhssZx/Plugins/clip64.dllOfflineAmadey dll abuse_ch
2023-01-18 08:36:10http://62.204.41.121/lend/myBUILDREDLINE.exeOfflineexe RedLineStealer ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-01-22 06:45:3046c8198822e882e10ae63be71b49e9d84cf2cb681406e70757ad45cae36c8b14exe 
2023-01-21 03:22:04a02ca4c50e7fe4d0a01c660880ed0ea992fc59a353caf82b7a40d14c5086541fexeRedLineStealer
2023-01-21 03:05:05fd6abc8cf0dc850dae68fe73929ae1865c410a19e3625b56e4b036fda550043aexeRedLineStealer
2023-01-20 02:29:04da9a898aeba9ed3dbf4d70fd12a8c886e1a7952c9bcb05952f87d9113c9df84bexe 
2023-01-19 12:31:045a96f601e3986178a0ec0a223261e9dabe79e3c50695b108e3e89c207af5036fexeRedLineStealer
2023-01-19 12:30:06b26a64868f91e56cd73d58f63293f662494f7e8797d3eb08ec789b2e31344a89exeRedLineStealer
2023-01-19 12:29:042c25b70f08a34cc52989882c4715854c4f488dacfa2c4a615ce5f8c265b21862exeRedLineStealer
2023-01-19 07:47:05069ce8ad7e119ba7c8678e9c12e55e63afd65b3598dc8e5b0551758dd326d310exe 
2023-01-19 07:46:0516e255ca2a06d93434303552da0a3a8fafde9e8d14f3f5ac42f4813bca6d60c0exeDarkTortilla
2023-01-18 08:36:08912f7d82ed878471ace2ca79a7e17ecad0b2bdf430570e646efaa940b01fc579exeAuroraStealer
2023-01-18 08:36:0788aa85f63ddbcfa1204202633336d60f9ac6e37510794be230bcfc64a50f243fexeRecordBreaker
2023-01-18 08:36:07c44bb6e89d6d5184f6fc10a8be170ba74af12d352e6988c9cf0730004a8a3ee3exeRedLineStealer
2023-01-18 08:36:07aaaceb896a7a8b0aa3c1946d93762420965c4328cfab43310f084813fec44afbexeRedLineStealer
2023-01-18 08:36:07caafa65df4fff5648321d0c3d69b77400b0fd4cb85671ba60b59fa0a2c28caa5exeRedLineStealer
2023-01-18 08:36:0757d08937a405243dd23e7c3666c53b5f2573639eb2c4f6bfa5b23e9c611392a1exeRedLineStealer
2023-01-18 08:36:07156da573614eadb656348d9ac7af4de07134dd7e1f66cb2df40260a830b7b520exeEternityStealer
2023-01-18 08:36:07103f83fe1d783a7a427f59f42754725a7b6f6be6b450a429907598ff831e4a54exeRedLineStealer
2023-01-18 08:36:061dfbea7dfa2a6feec6e27b1e1d39169aeece1a4a716f08fc7726d0a08fc567ccexeRedLineStealer
2023-01-18 08:36:06663c3fca0878472db0ecd4ec4fdc67690c1de08fa5c228e1911b6278cf83a0a6dllAmadey
2023-01-18 08:36:066f3491d165ac055811596f2d64ad107247e19b333d79316c0ac96c93787c1e1aexeXWorm
2023-01-18 08:36:056dd2706b26208b0dab625fadab85731bdc6a8c169f4b4db057364ae22ad55b00exeRedLineStealer
2023-01-18 08:36:04e00993941f556c5d3eca07ea50c7204868cd55e101fc683e15967fdc1136277eexeRedLineStealer