URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 65.20.105.177
Firstseen:2026-05-27 20:07:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-05-27 20:07:10 65.20.105.17765.20.105.177.vultrusercontent.comNot listedAS20473 AS-VULTR- ESyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-27 20:07:13http://65.20.105.177:8080/cloud/Screenshot_25_0...Offlinelnk ocx opendir WsgiDAV DaveLikesMalwre
2026-05-27 20:07:12http://65.20.105.177:8080/cloud/712419111124.ocxOfflinelnk ocx opendir WsgiDAV DaveLikesMalwre
2026-05-27 20:07:10http://65.20.105.177:8080/cloud/mscom.ocxOfflinelnk ocx opendir WsgiDAV DaveLikesMalwre
2026-05-27 20:07:10http://65.20.105.177:8080/cloud/mscomctl.ocxOfflinelnk ocx opendir WsgiDAV DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-27 20:07:10be7b80f42b0d859b7afaeefca04e46dc10fb5c0a532692bbbfef2924254d1175dll  
2026-05-27 20:07:10d64a7e0299a537e211114baaa7f1341f5018a1e432d39d6aebb26b1c98c38da2dll 
2026-05-27 20:07:096922b319dc96d020738bcf466c4d6d9233e4767b68592e1fd9258a232f166ce1dll 
2026-05-27 20:07:09a232f568b4a04e9a6914db41d63353019037e8cff4cc3b7af3d692746a32b796lnk