URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-10-25 00:06:30 | 141.8.197.42 | techproxy.from.sh | Not listed | AS35278 SPRINTHOST | RU | yes |
| 2022-07-26 15:12:06 | 141.8.195.65 | hlokk.from.sh | Not listed | AS35278 SPRINTHOST | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-07-26 16:32:05 | http://a0669976.xsph.ru/sgot.exe | Offline | exe | |
| 2022-07-26 15:18:05 | http://a0669976.xsph.ru/upd.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:17:05 | http://a0669976.xsph.ru/bazzy.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:13:06 | http://a0669976.xsph.ru/r.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:13:05 | http://a0669976.xsph.ru/v.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:13:05 | http://a0669976.xsph.ru/x.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:13:05 | http://a0669976.xsph.ru/g.exe | Offline | exe RedLineStealer | |
| 2022-07-26 15:12:06 | http://a0669976.xsph.ru/b.exe | Offline | exe RedLineStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-07-26 16:32:05 | 4501d85e86cf567897f6c4ed7b1f7877cee415f92760566404b1f1daf8f4d6e5 | exe | Zyklon | |
| 2022-07-26 15:18:05 | 122b85288059eb5e20318712aa2569b8715dcf2d0edddb35afa0cf97944d5688 | exe | RedLineStealer | |
| 2022-07-26 15:17:05 | 2334e0b1e63b8c4c212c345c86e10bfc5930a355830a591a201751ed364bb47a | exe | RedLineStealer | |
| 2022-07-26 15:13:06 | cef86aaea77b2d3f0d449003b1dffa9e8af91d4d1f711f0da7138db754f9d2ab | exe | RedLineStealer | |
| 2022-07-26 15:13:05 | cb669b48124cb5fa6b643aada9e773454d0db48e614cc54b45ecc319444b308d | exe | RedLineStealer | |
| 2022-07-26 15:13:05 | 4e53778b6d2025b040ac38edf07dd9c31cae71628c231b227a7256c12a788cfc | exe | RedLineStealer | |
| 2022-07-26 15:13:05 | e4ab02856caf1651c81f99bac789bb0570925f64afebc64701e487ad5dec0aa7 | exe | RedLineStealer | |
| 2022-07-26 15:12:06 | 36ac1377c88fb5dd7ffb82c918ee1e07fa75ee2ff50f6ce129e859152bf0dc44 | exe | RedLineStealer |
RU