URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 94.156.65.178
Firstseen:2024-01-14 16:04:05 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-01-14 16:04:07 94.156.65.178Not listedAS208893 sparks- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-01-15 07:58:05http://94.156.65.178/tool/2.exeOffline32 exe LummaStealer zbetcheckin
2024-01-15 06:21:05http://94.156.65.178/tool/1.exeOffline32 exe Vidar ext zbetcheckin
2024-01-15 04:43:06http://94.156.65.178/tool/3.exeOffline32 exe Formbook ext zbetcheckin
2024-01-14 16:04:07http://94.156.65.178/tool/4.exeOffline32 exe Vidar ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-15 07:58:058d800fb136b4e8e08ddacec182971201f121860e309e1dccc57a1cf7eb16f2cbexeLummaStealer
2024-01-15 06:21:05cbab2f6767f4b80287642e550cd8aaed4ca8bc58cc8dcd48c3ef6d3a65975a94exeVidar
2024-01-15 04:43:065c7af580a755c6428982c8e3c8ca29efc031d6897e3d8ff91570acdcf3961fe0exeFormbook
2024-01-14 16:04:0735178ea71fd6bc4c15e2c302613f3c0ff5579b0669e800a24dc30d68e0328942exeVidar