URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 88.119.161.219
Firstseen:2022-12-24 15:08:03 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-12-24 15:08:10 88.119.161.219new.geliusala.comNot listedAS61272 IST-AS- LTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-24 15:08:10http://88.119.161.219/prettyremote.exeOfflineDarkTortilla drop-by-malware PrivateLoader andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-25 11:35:53d0bfc35b60cf80f2b52779d06d08ddf2d01f784b0f28fed75d58aa3366656a3bexeDarkTortilla
2022-12-24 15:08:0415347a41c9a5909a7fffbc8f89c7b0154dafe57ac80e9a153ffda2936f63b24aexe