URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 12:53:15 | 65.109.16.61 | server.cloudvps.pk | Not listed | AS24940 HETZNER-AS | FI | yes |
| 2022-10-23 17:44:14 | 65.108.125.117 | server.cloudstorage.pk | Not listed | AS24940 HETZNER-AS | FI | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-10-23 17:44:15 | 476a7e4c2495b79b64e20453751128f72379373127153204f2d9ce951d4d9bf4 | exe | CryptOne | |
| 2022-10-23 17:44:14 | 8952757228f9e783df3feaaa62ffb448ae49d66bda7f484c1447d48968e3a463 | exe | RedLineStealer | |
| 2022-10-23 17:44:14 | daaa0aa0dc9c10baf105b5aa376724f2cee7ea5b6d01372b2504b1157437c294 | exe |
FI