URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: amssh.co
Spamhaus DBL :Malware domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-04-20 07:58:03 UTC
Total malware sites :1
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-11 14:04:54 172.172.168.240Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USyes
2025-05-09 09:14:36 91.92.46.76SBL680015AS41745 FORTIS-AS- USno
2025-04-26 13:19:36 91.92.46.219SBL680015AS41745 FORTIS-AS- USno
2025-04-25 17:04:46 176.98.186.23h23.hevefuqo.ruSBL679573AS210369 MXCloud-as- SGno
2025-04-20 07:59:10 147.45.44.233Not listedAS212165 kvmka- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-20 07:59:10https://amssh.co/file.exeOfflineStealc Vidar ext abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-09 09:14:359b28518ef923e7c7b010f2255b30bec3ff23095d9cf3ed55376f429ad5904489exeStealc
2025-05-06 23:22:29998751c996069cea751c941d8e691275ce01dc66959dfc436e4266d7218565e5exe  
2025-05-05 16:45:136cc52ef5b6612ef69527088147009ed8c171850205c958a361701246a76746f2exeStealc
2025-05-04 22:52:15f1d717b661575febfa27037e1f14b45d2513d93a8706fbfc268dca4b57390312exe 
2025-05-04 15:52:11afc72f0d8f24657d0090566ebda910a3be89d4bdd68b029a99a19d146d63adc5exe 
2025-05-04 10:41:3039aff20c236f7a536781e3e137ee4e7a41f49c9a10c1e869797a9f210deceaa6exe 
2025-05-03 17:09:05629d83659df3e1aaa04b6c296a3cf8e2248033e9d1ff422e350453d77cb2a5f0exeStealc
2025-05-03 10:47:331fdb17242e1cc496b7fb830a953eacf74580322ab81fe6f9def02fdd32a28858exe Stealc
2025-05-01 13:14:05591e26f49edf70e4a20e0044b40e56b0b446c61840c6696e2e831bd983964eaeexe  
2025-04-30 16:02:3668a5b05041f2078b3c2df3b87a79c1da6bc0e7075f7deb60f9426c11630853d0exe  
2025-04-29 19:55:54e69fc4c93aed589421ff16c2e3f77bd47aedfcc5c64434c5743f1a7a5bc4f90cexeVidar
2025-04-28 18:11:062696af2163d986842f833c530d133027f3b7b83ab044179695f2c2a976a91a59exeVidar
2025-04-28 12:21:12fe933db152695b2405c6dbc0248b78229bd9c0083c660f9e472a4a47e8f73e40exeVidar
2025-04-27 18:32:506ed676c974e6959136b26c279d9a78413ae41b44c34de2bd94a08d6c0b93fbddexe  
2025-04-26 15:57:47f78892355e6019ae60c1e830826cda523496ce2cd70d0e4ce4bec9a085f47b21exe  
2025-04-26 15:00:138a51d26be760d2515fdbe742bc84bd08d05d4e7f665bdd3c37b8c425f839675eexe  
2025-04-25 10:15:3195ab68001831160ee128a083a4f27e5e2e07449110439c74ac01fb2de9ca431fexeVidar
2025-04-23 19:14:030c0bcfdc98ed7f5fab260de24a5b29e336c88080dabd0a1238b2bc392542c18cexe  
2025-04-21 16:07:10c5bfaddfb2cb99e2935940e5783fc49c6baa8db5bdf4f2e32c7df8d044ef9711exeVidar
2025-04-20 08:46:49fd39a100de7ae6efc732edeab31a89313d0be7e0540acffc04f6ed707c48c48dexeVidar
2025-04-20 07:59:09d28bc1b8975df8985c266826dc2111d6c50989fce391f72327171df965231166exeVidar