URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.239.148.93
Firstseen:2023-12-13 12:02:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-12-13 12:02:16 91.239.148.93Not listedAS199058 SERVAONE- PLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-12-13 12:03:13http://91.239.148.93/HoldV.exeOfflineCoinMiner exe vxvault
2023-12-13 12:02:16http://91.239.148.93/1.exeOfflineArechclient2 exe vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-13 12:03:13078ea4e8b747ab8e2019a1c87081836c267585fa06616472e3acbb0b83634b1dexeCoinMiner
2023-12-13 12:02:16cf0c7d8987626b0d2f0115ca56a525762382a4e453365ea740caf733fd8a908eexeArechclient2