URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.92.250.98
Firstseen:2023-12-01 05:50:05 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-06 19:26:15http://91.92.250.98/02.08.2022.exeOfflineCobaltStrike ext exe abus3reports
2023-12-01 07:16:06http://91.92.250.98/thursdayyyyyy.exeOfflineAgentTesla ext exe abuse_ch
2023-12-01 05:52:08http://91.92.250.98/droidfileftpwithcontactreco...OfflineAgentTesla ext asciii Encoded abuse_ch
2023-12-01 05:50:10http://91.92.250.98/primebase6444444.txtOfflineAgentTesla ext ascii Encoded xworm abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-01 07:16:060ec323f55808814136b3c1059277ac2a2753955676218a13aacc73565fea684eexeAgentTesla
2023-12-01 05:52:082c337b83a3e70cb50d6973455a2f02a99ed0dac287101f7c9603263b3dc5e30ctxt AgentTesla
2023-12-01 05:50:096c7b82cc06d0a48a81f4c0569763f205b3b256ca333f4137acde0d7007b6a208txt AgentTesla