URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.92.243.139
Firstseen:2023-11-14 14:08:04 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-14 14:08:38 91.92.243.139SBL686267AS214943 RAILNET- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-23 07:05:10http://91.92.243.139/files/InstallSetup24.exeOfflineexe abuse_ch
2023-11-14 15:02:11http://91.92.243.139/files/InstallSetup4.exeOffline32 exe glupteba ext zbetcheckin
2023-11-14 15:02:06http://91.92.243.139/files/wsclient.1.25.win.03...Offline32 exe zbetcheckin
2023-11-14 14:57:16http://91.92.243.139/files/11.exeOffline32 exe Socks5Systemz ext zbetcheckin
2023-11-14 14:08:38http://91.92.243.139/files/InstallSetup2.exeOfflinedropped-by-PrivateLoader glupteba ext GuLoader ext andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-24 01:06:51b2e138ea3c9e6424d54f592ffdd5db5fd7cd5c762e34b76a598b0b6e709f12a4exeGlupteba
2023-11-23 18:44:333ee5492debd76443410d65a52c16c55b183cce66bf428ada82db1dd89e36e194exe  
2023-11-23 07:05:105d8294241f1bd78af90f6b48ff264e7bf9f48746db2be3a216c56a3e9877b3d1exe 
2023-11-22 18:06:39ba9b6e4e3c24b040f6a0cb4b6e6e37e0f0529c75bcc357f6abaca8561a67434fexeGlupteba
2023-11-22 00:57:314329b1deaf46731c0e7a55e4ca9adaefa6daa9f8f6015c8ece22dee784898c18exeGlupteba
2023-11-21 01:44:2686a7de9388ee50b02a57d831d4539ba2c32877402a952ac8dcd1c7cf7c3e4cedexeGlupteba
2023-11-20 19:40:4913e767854d12c3a62a83c90839d9b3041fcca033c06ae1452de9704886e4948bexeGlupteba
2023-11-19 18:34:453310176989a25f60f2406a1da8ebfd962b27c07ee107b3472faff5e1df3857c9exeGlupteba
2023-11-19 00:53:44978708f8b2ce3fda82c9376420dc023396ee686d43962675dda5f18b3b749753exeGlupteba
2023-11-17 01:12:29addcd44ed648980e8bed20517c5fddf1dde5da3dac960339f4d049cd974daf5fexeGlupteba
2023-11-16 17:29:12745d794fd8a4efccfa11efa67e9232f31257931e4d846b2ab0a92bb8c4aea7d8exeGlupteba
2023-11-16 01:12:18c99f57b763d90598609eb0b585ca8399057531d171021d3052efdefe26289117exeGlupteba
2023-11-15 18:00:002aaa4c723b5868576aa1be98426763d3c75b1255aa639516c46d5867d2e970a4exeGuLoader
2023-11-15 00:53:3693f4f7dd1458ebc9caa287fe4a81737a417a75ab8e3a4a150c5c907f87b51d11exeGlupteba
2023-11-14 15:02:11e26a36702257f07a25adc0e5b1a3ceeabcbcb18b63c8d83c0ccb988f848e4a08exeGlupteba
2023-11-14 15:02:06df5397b08e1b72fbf42290033aa11934e895488c93b76e608542fbb49d2e0f98exe 
2023-11-14 14:57:16fed92b12cc0fbc75bb1d1c661e1675f6e20d27d6d03d25174536d71125cb7a0eexeSocks5Systemz
2023-11-14 14:08:387e2fc238252c47231d37ab938055672b07423ce2688bb32cff3b97dc179fee9bexeGlupteba