URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 85.239.151.38
Firstseen:2026-02-25 15:39:05 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-25 15:39:08 85.239.151.38illcrook.ptr.networkNot listedAS19318 IS-AS-1- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-25 15:39:08http://85.239.151.38/02.08.2022.exeOfflinecensys CobaltStrike ext DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-27 02:25:5773ed7f62c7c320c3a2ee23a2eac83fd9c775eb1c3ac83a73f3ffd9d14b1aafe5unknown  
2026-02-25 15:39:0744c4efc9ad302c8ad94092e7f73492215b48d3a1a3f725b9f450e45881bb8463unknown