URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-09 14:55:19 | 202.10.43.74 | digul.satu.rumahweb.net | Not listed | AS58487 CRI-AS-AP | ID | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-11-09 14:55:19 | https://aplikasiikan.com/loaad.msi | Offline | Arechclient2 msi |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-11-19 03:48:27 | f99001fe83c63e2444ea8e4f79a8c92057dea8e40e946bd2f58ad0659b05c62c | doc | ||
| 2025-11-15 07:20:33 | a6aaa9632dd5f76d126c01dbc9ea45bcc6ea77461e1692d03c5bb85f1b7f37b9 | doc | ||
| 2025-11-09 14:55:19 | 77dec68adc9d69b54bb2121cdb1d0a188e4da2f750958062311f1be8133fa3b0 | msi | Arechclient2 |

ID