URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.92.241.91
Firstseen:2023-11-27 16:20:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-27 16:20:11 91.92.241.91SBL686267AS214943 RAILNET- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-27 17:35:08http://91.92.241.91/files/Random.exeOffline32 Amadey exe glupteba ext zbetcheckin
2023-11-27 16:20:11http://91.92.241.91/files/InstallSetup2.exeOfflineAmadey CoinMiner dropped-by-PrivateLoader glupteba ext Vidar ext xmrig andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-04 01:18:29f5be7905ff4e3fcff8697d08de785719c1eeac0d5ac5b8373917de764cc0cac1exeGlupteba
2023-12-04 01:02:1081bf0cf226609f2e57348cff8cd45d5ecca385e113fd7f44a330aabcfc55381dexeAmadey
2023-12-03 17:27:03799cde477706f70c4f7ccdf560cdcafa60012683440eddecfe2bc2ef0c839e2bexeGlupteba
2023-12-03 17:26:158c05ce7f2040a7ea25080f7fa2b060052c1996dca83a3ea0c4b451cc1e16ced6exeAmadey
2023-12-03 00:53:128e28141aa8e1ec61b3a1bf29dca643466cfa64788d57c9d0c259d6e865b4dfc0exeAmadey
2023-12-03 00:51:21894d4384548ba2e383a7568b57e5fcfd18d36dab8552142dd7f8c02457b9e4aaexeAmadey
2023-12-02 14:25:0290c705c231a5e9e61a41474b00d64b321e85df7f814b398fe11ba16287d98864exeGlupteba
2023-12-02 14:19:313f9dea18016627459bb9a1dc0e11c85ba9b3e550f114dd1cd05357a4ffa1da62exeGlupteba
2023-12-02 01:08:284c54ba7f97c9d5c547781a4e99f6324cc5084777d7318457a5077af17d63b7a7exe  
2023-12-02 01:00:58ffd6e1c96829784a3a19881b1e0e65ed562671a0315f65750fab10dab81477e1exeGlupteba
2023-12-01 16:44:18b7fc28f25a4aa0b3a8030419c4aa0f0004e15f67496c5c71fcebbe4b1b583f58exeGlupteba
2023-12-01 16:27:55eff416f17b83327e6911308b2b9678f52fb4b4d20b99a96f43c2478e5dcc10f2exeVidar
2023-12-01 01:19:04bd499108bc5684a3c356097facf9783a8f2331f63d7749363bb6c739ccc9c248exe  
2023-12-01 00:57:40ae9dec17418ed06f57af2df42fc52c285416996c460115ad3a5d8929f0867951exeGlupteba
2023-11-30 16:35:55347d793c12fd82dc8e0841d24d2f8cb9743534bd0f156b302b5cb7b07bb5d319exeGlupteba
2023-11-30 01:59:1557ed1aa9bb3827fb3ce2ced5cf5e45b442388031c52db6d0b602497641eab20dexe  
2023-11-30 01:57:15b7cedaa26031eaa3bd108abb42e4a90738ca4606e7b305166b12a360f98cc251exeGlupteba
2023-11-29 18:17:52e7729036b9e69fd7dcf07e6ee0c8dd71a4b1432f55ab4e48572634de8d44b673exeGlupteba
2023-11-29 18:09:319e799a21708c94de84259db6e935fd2f2bae41124fe31ff43a6ea9a1a6989db8exe  
2023-11-28 16:54:253e9c5961ee8a2a0c30539e79f9ddfb8870f5488d9571562fb1d90c8440dffdf3exeCoinMiner
2023-11-28 00:33:4175f4bd481c7ee94f6e52fdb70de7db8243085067393a58ab14492452c4419297exeGlupteba
2023-11-27 17:35:08e5f297504744c01bec8a5903f55b7fcc149e39a334a1c1cb80960878604b5012exeGlupteba
2023-11-27 16:20:0990a3094c222cdadd6986b4d18e2c6ee5172484316ebd18a05167e2f458e17270exeGlupteba