URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 92.52.217.11
Firstseen:2022-11-03 09:06:03 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-03 09:06:04 92.52.217.11entrust.bandpitch.buzzNot listedAS46450 PILOT- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-11-23 17:25:05http://92.52.217.11/microsoft/csrss.exeOffline.net exe Loki ext msil jstrosch
2022-11-21 20:07:04http://92.52.217.11/documment/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-17 15:07:04http://92.52.217.11/Explorer/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-15 11:37:05http://92.52.217.11/DriveX/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-11 06:27:04http://92.52.217.11/dataspace/csrss.exeOffline32 exe Loki ext zbetcheckin
2022-11-10 12:45:05http://92.52.217.11/msncloud/csrss.exeOfflineexe Loki ext opendir Quakbot ext abuse_ch
2022-11-08 15:43:08http://92.52.217.11/cloudDrive/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-07 12:36:04http://92.52.217.11/spaceDrive/csrss.exeOfflineexe Loki ext opendir abuse_ch
2022-11-03 09:06:04http://92.52.217.11/spacedisk/csrss.exeOfflineexe Loki ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-11-24 11:14:04837a755371d9da370735e9ae34e6405d328e7c1bcdfcb4ed0744aa03a2bbe447exeLoki
2022-11-24 08:41:4385381cce386d43501119062a68fa2ea33428c230d622381d9962aafad694cb77exeLoki
2022-11-23 17:25:05cdf391a25039e52f901e570ec398ee0cda880b9ea1275ebfd2272e51474c4a44exeLoki
2022-11-23 14:41:03736330aaa3a4683d3cc866153510763351a60062a236d22b12f4fe0f10853582exeQuakbot
2022-11-21 20:07:046b2e3bc145fce8f07baf85b39c4c86491a7fa02dd964257fee2abe5920972615exeLoki
2022-11-17 15:07:04e00ec00017239c89d937e5566508553480539ef0da52fc97441b5c985192c30eexeLoki
2022-11-16 07:23:08eb1ffa7856bf82fe3781c33dee834a9c7c1d4d7067e0c70e78105b0ab52f8519exeLoki
2022-11-15 11:37:05e879f25101448fd663c425bce1206d4e8ff8c66f95a292dcc1f34576d2bb5d80exeLoki
2022-11-11 06:27:0454a803a43c88a1dc7866fed21425200edb8227351c77142c308821f9e23a7c7eexeLoki
2022-11-10 12:45:05cc806bea95a7e99e911d557099bb5a15e4659b9cc3303ae271c69ad23b042114exeLoki
2022-11-09 01:43:137a037b203ec93f6294986caba1bf5bc75ee68be47bb6a0622a42500d97851d5dexeLoki
2022-11-09 00:31:15d943255185ae2844e018149b4cd7468a4b6f96559456fdc4fd80b4ecdfd49045exeLoki
2022-11-08 15:43:06e9adc2a8a1d94fb13c2b4c6343c4dae56accdeea3b37004b7f17cfbe30c1bd85exeLoki
2022-11-07 12:36:049688673c723ed329fd87bd07812c945d7734e54fa5a27cb79a2ef982234337dfexe Loki
2022-11-04 03:49:33db7a33f2a3884c2f0f37ffdf329af20f5a0103b41fa26d2dacabdba15b3fe693exeLoki
2022-11-03 09:06:0493817bec58278b88fae815045d7b2705dcdc92dd78a776cc9232c3b6ddc97d78exeLoki