URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 94.156.65.121
Firstseen:2024-04-04 19:01:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-04-04 19:01:10 94.156.65.121Not listedAS208893 sparks- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-06-17 18:46:07http://94.156.65.121/miner.exeOffline64 CoinMiner exe zbetcheckin
2024-04-04 19:01:10http://94.156.65.121/kev.exeOfflinedropped-by-SmokeLoader Smoke Loader ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-06-17 18:46:0774895cc8a75a906c088dcb303aadb2967fcd9469eb70a7979351421a33e439f3exeCoinMiner
2024-04-04 19:01:0812d3dc8a4fd8a2ebe6a839cce59920156d55e8d06fe2a5c95ad60419086877bbexeSmoke Loader