URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 08:33:11 | 162.43.104.50 | sv14649.xserver.jp | Not listed | AS131965 MAINT-JPNIC | JP | yes |
| 2019-12-10 07:17:06 | 153.122.170.20 | Not listed | AS131921 MAINT-JPNIC | JP | no | |
| 2018-06-28 04:29:17 | 153.122.44.124 | et.ptr116.ptrcloud.net | Not listed | AS131921 MAINT-JPNIC | JP | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2018-08-01 20:43:08 | ddfa667a6805bf8b9216feb8df15b1590c340914d7142aa142ecb858d117ba9b | doc | Heodo | |
| 2018-08-01 20:38:01 | 207f084b0cc2eb26c4a7c680a886e3f9bd65f45eed695d504743d6bbaafa9856 | doc | Heodo | |
| 2018-08-01 16:42:48 | e1e6f47f76667d41ff54aa4b94741b5a0faccc5ef1a002694b83a0816ab7722f | doc | Heodo | |
| 2018-08-01 16:37:15 | e1e6f47f76667d41ff54aa4b94741b5a0faccc5ef1a002694b83a0816ab7722f | doc | Heodo | |
| 2018-07-21 06:02:26 | 9eb5ebf4950818df9294072543535ab5bf97a9af906b2c14909a7c79445250cf | doc | Heodo | |
| 2018-07-20 04:53:12 | 180fd095fac220876a81b870f81af36d1a4b15b7cee4327354e4a06301032f1e | doc | Heodo |
JP