URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 08:48:33 | 85.13.167.21 | dd54724.kasserver.com | Not listed | AS34788 NMM-AS | DE | yes |
| 2021-04-27 03:48:08 | 92.204.55.62 | sh10128.ispgateway.de | Not listed | AS8972 GD-EMEA-DC-SXB1 | FR | no |
| 2021-03-29 14:58:04 | 80.67.17.213 | Not listed | AS34011 GD-EMEA-DC-CGN1 | FR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-03-29 14:58:04 | https://botschaftvielfalt.de/fa8vyq.zip | Offline | Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-03-30 21:22:20 | 0c197468076c14f7b6c4fd095009ff628970f2c8d408131f7afd306b5e65eedd | dll | Dridex | |
| 2021-03-29 17:53:51 | eb120a9eaa04f976f5bee426c0b19c8e2b000c71390d1c79c0dee47a2712ee4a | dll | Dridex | |
| 2021-03-29 15:56:06 | 60988ff09b0d229689af66e2045a647d162cc561b52c8eee13db247681b16ea7 | dll | Dridex | |
| 2021-03-29 14:58:03 | 7ec6d4c4d98a1901c2a64bea8f5e1ca476ea85d6d52a6d6810531f56387e7859 | dll | Dridex |
DE
FR