URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 08:57:00 | 101.53.145.145 | weblynx.getsetlive.com | Not listed | AS132420 E2E-NETWORKS-IN | IN | yes |
| 2020-09-19 08:59:41 | 208.94.232.134 | Not listed | AS40824 WZ-US-40824 | US | no | |
| 2020-07-16 16:23:08 | 208.115.234.234 | 234-234-115-208.static.reverse.lstn.net | Not listed | AS46475 LIMESTONENETWORKS | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-07-17 06:14:36 | https://amt.co.in/d.exe | Offline | AZORult | |
| 2020-07-16 16:23:08 | http://amt.co.in/111.exe | Offline | AZORult |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-07-19 10:28:10 | 44c9345759f82e06403ff2312e21c4c487c7445707bc28e62046268d141afd16 | exe | AZORult | |
| 2020-07-17 06:14:36 | 980ba1a8bbabaea3660d93c50b0467c22e1934ca026eeed63339c2d36f888294 | exe | AZORult | |
| 2020-07-17 04:25:57 | 59e39b6123ed1218d7ae3b4406b3e06c1fc84ecb8fafad05e762b9867c77248b | exe | AZORult | |
| 2020-07-16 16:23:08 | ee0f914953c77d22365c0ae6a02e93eb5bfc55c5bee13149aa50a2acb2a2095d | exe | AZORult |
IN
US