URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 86.54.24.29
Firstseen:2025-12-10 12:45:08 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-10 12:45:15 86.54.24.29Not listedAS208885 NFS-AS- LVyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-11 06:49:08http://86.54.24.29/Wesnoth.exeOfflineexe abuse_ch
2025-12-10 12:45:15http://86.54.24.29/Renewable.exeOfflineAtlasAgent exe DonPasci

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-11 06:38:40f1e80eb9ca74f7ee12a6b005baaedc54ca58b7c65f9c45a35275a89c9eac93a7exe  
2025-12-12 18:28:33ecf64162e512ba693f0372d85db18d367fe05f2abd3799ca45426f152a982591exe AtlasAgent
2025-12-11 06:49:088539f83c96a0aee219a8277444a3a50c1137772aea2db845447e33009b36d88fexe 
2025-12-10 12:45:1538346fbdc7b234d17e12d2608bf87806de05561e5e6dcdfd6a81f76dbc5c8a09exe