URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.92.242.251
Firstseen:2023-12-05 16:30:08 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-12-05 16:30:12 91.92.242.251SBL686267AS214943 RAILNET- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-12-06 16:31:35http://91.92.242.251/Ehthcrwayn.exeOffline abuse_ch
2023-12-06 16:31:35http://91.92.242.251/Anzjgnbmuz.exeOffline abuse_ch
2023-12-06 16:31:35http://91.92.242.251/Kldxhd.exeOffline abuse_ch
2023-12-06 16:31:35http://91.92.242.251/base98.exeOffline abuse_ch
2023-12-05 18:00:37http://91.92.242.251/Vonupajtmf.exeOffline64 exe zgRAT zbetcheckin
2023-12-05 18:00:18http://91.92.242.251/Ygmpogts.exeOffline64 exe zbetcheckin
2023-12-05 16:30:12http://91.92.242.251/Omnknufm.exeOffline64 exe zgRAT zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-05 18:02:22d30a0536849fe6a5e1fc223f1cbd784cc83b8889ecb2e46b879cf56fb0dff03bexezgRAT
2023-12-05 18:00:182ba97ed5f4d0a8ea8b7922ed7ba5460d63e03e27e91a32ef46438fd0e73576d1exe 
2023-12-05 16:30:11acd49294aa9aaf8f0a8b057438a3783038822868c8eb98a4289bb7f4ec54268eexezgRAT