URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-30 02:24:42 | 193.227.129.145 | 2.qservers.net | Not listed | AS397423 TIER-NET | US | no |
| 2020-05-05 17:20:15 | 67.225.141.109 | twentyfive.qservers.net | Not listed | AS32244 LIQUIDWEB | US | no |
| 2020-04-27 22:28:34 | 51.89.21.15 | ns3148367.ip-51-89-21.eu | Not listed | AS16276 OVH | GB | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-04-27 22:28:34 | http://brightstore.com.ng/cjy/cjcrypttt.exe | Offline | Loki |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-04-27 22:28:34 | 008c8a71668c7c7b83c38e28700e78ded26da69e6cddcb3cf4c85305ae27b7fe | exe | Loki |
US
GB