URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 79.110.62.142
Firstseen:2023-02-21 12:45:05 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-15 14:57:09 79.110.62.142Not listedAS213893 IPTR-AS- BGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-02-23 02:41:06http://79.110.62.142/O--O.DOCOfflineRTF zbetcheckin
2023-02-23 01:13:04http://79.110.62.142/8890/vbc.exeOffline32 exe zbetcheckin
2023-02-22 10:29:03http://79.110.62.142/O--OO.DOCOfflineLoki ext abuse_ch
2023-02-20 15:12:04http://79.110.62.142/8891/vbc.exeOfflineLoki ext lokibot ext James_inthe_box
2023-02-19 07:34:04http://79.110.62.142/OO.DOCOfflineRTF zbetcheckin
2023-02-17 01:29:04http://79.110.62.142/O.DOCOfflineLoki ext RTF zbetcheckin
2023-02-17 00:41:04http://79.110.62.142/3545/vbc.exeOffline32 exe Loki ext zbetcheckin
2023-02-15 15:38:05http://79.110.62.142/2202/vbc.exeOfflineexe Loki ext abuse_ch
2023-02-15 14:57:09http://79.110.62.142/2203/vbc.exeOfflineexe Loki ext opendir abuse_ch