URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 81.163.246.9
Firstseen:2021-05-14 13:43:03 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-05-14 13:43:05 81.163.246.9Not listedAS51973 KOLT-AS- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-24 20:27:06http://81.163.246.9/Videos.exeOffline32 dcrat exe zbetcheckin
2021-09-02 03:12:03http://81.163.246.9/eth.exeOfflineCoinMiner exe zbetcheckin
2021-09-02 01:54:03http://81.163.246.9/xmr.exeOfflineCoinMiner exe zbetcheckin
2021-09-02 01:36:03http://81.163.246.9/rvn.exeOfflineCoinMiner exe zbetcheckin
2021-05-14 13:43:05http://81.163.246.9/act++.exeOfflineexe RedLineStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-27 21:02:54a39dbe692ce05a75c1243c4769d93783a651b61284c87670824e2ebc4169f831exeDCRat
2022-02-24 20:27:0628b792e7ea9e3a4a7e511f0710628321157604ab34d445c22c3f485a24052b9aexeDCRat
2022-01-13 22:50:53b41a1c51ed21c0c7c1a80a9b196b89de242171a41768b631c6e600a40554b434exe  
2022-01-13 22:41:38b41a1c51ed21c0c7c1a80a9b196b89de242171a41768b631c6e600a40554b434exe  
2022-01-13 22:39:52b41a1c51ed21c0c7c1a80a9b196b89de242171a41768b631c6e600a40554b434exe  
2022-01-01 07:04:05fa8fb27be6e79dd6fd293574b044061d51d40446887c3b34fed1ab55e0f58c7aexe  
2021-12-15 18:52:38c5bb6e7252e75503d583bf11d6cf300d7ad7db2d6ee149e4e6ba988f261e5463exe  
2021-11-22 23:41:0092f7ac06c7012a1ca4eaab3cad720e03d0889b89fba7931b934e160f2cf72022exe  
2021-11-10 23:40:551b675f560912f81f703d2037fa6d20360ed66db71f66865bae66ec8099a45eb6exe  
2021-11-10 23:09:03d1b8de764f5d4717a1effc094ff3cb040f31eb0cfadac82c327077d9bd7d35e8exe  
2021-11-10 22:58:32935e1575ed4a358d34285eb9e90be5a16e842919950c397356e88ce064b40dc9exe  
2021-11-10 22:21:50a879674b8162a1bfd7da661db3fc23accbd003e328409b47df518f8bc44de030exe  
2021-11-10 22:17:5009a947547e984f3dbf05cf1333797bf282a56d50586deef4974d09897658cf5fexe  
2021-11-10 22:17:29b82a9c29a8dad7cd674e7edf3282a0d85960fbd42a587bfcb21c728e35d263b4exe  
2021-11-09 19:01:42ae7dd486d3dd656f3d4c8060a35209b895067aa2f8edb211bbd06d82e3306596exe  
2021-11-09 16:18:27ae7dd486d3dd656f3d4c8060a35209b895067aa2f8edb211bbd06d82e3306596exe  
2021-11-09 15:37:29ae7dd486d3dd656f3d4c8060a35209b895067aa2f8edb211bbd06d82e3306596exe  
2021-09-02 07:15:28af0d62ecd9bcdde3f9d71c43c354adc96f09d46e676768f8889f98dc9e4308d2exe  
2021-09-02 03:12:03bdbf24537950b4bb8ca32e92dc5934fd651792db3452c748d7893da61aca1710exeCoinMiner
2021-09-02 01:54:03760ad5c308f4bdc50cc521c93bb3a88c8c25f330234a5086c3b7c82e743f82feexeCoinMiner
2021-09-02 01:36:0399a4483312a49933b40f2ce227cdc2a820a595eb465bc488a97e5e59fd94843eexeCoinMiner
2021-05-14 13:43:0498c9ef926c5ba64ed79f5788b4222df8aa5f7193636febe47b190795478d98ecexe RedLineStealer