URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-09-11 22:59:54 | 185.111.111.156 | 185-111-111-156.bunnyinfra.net | Not listed | AS212238 CDNEXT | DE | yes |
| 2026-09-11 20:18:18 | 185.111.111.157 | 185-111-111-157.bunnyinfra.net | Not listed | AS212238 CDNEXT | DE | no |
| 2026-09-12 10:49:27 | 185.111.111.155 | 185-111-111-155.bunnyinfra.net | Not listed | AS212238 CDNEXT | DE | no |
| 2026-09-13 10:41:14 | 185.111.111.158 | 185-111-111-158.bunnyinfra.net | Not listed | AS212238 CDNEXT | DE | no |
| 2026-09-12 04:41:57 | 185.111.111.154 | 185-111-111-154.bunnyinfra.net | Not listed | AS212238 CDNEXT | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2026-09-11 20:18:18 | https://adpayworks.b-cdn.net/download/1.1.2/AdP... | Offline | msstore revoked-cert signed WailsLoader |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-09-11 20:18:18 | 860fc154444167d8411d3796d047093ad242fcb071eb645e845ea9e048c15cb5 | exe |

DE