URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 80.209.233.231
Firstseen:2021-09-24 06:14:02 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-09-24 06:14:04 80.209.233.231Not listedAS212531 Interneto-vizija- LTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-09-24 06:14:04http://80.209.233.231/nscvhost.exeOfflineDanaBot ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-09-24 19:24:278174054c67035ea2aef476a22bb14270d36299cc62adfd2dc2900a7686ce156eexeDanaBot
2021-09-24 15:21:15867317f0875ba0635d62393278994b110ea94179d6e736fa7891a83983822143exeDanaBot
2021-09-24 08:51:5673e761de4a8be29d7dc04e48a47f417917cf2f37a27dfb9db45069d4ccb66cecexeDanaBot
2021-09-24 06:14:0334f3e9fff45b86f0d41196592ac0c8df6852bae2724aad54f822f8f5983a702eexe DanaBot