URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2021-10-11 06:31:09 | 185.178.208.148 | ddos-guard.net | Not listed | AS57724 DDOS-GUARD | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-10-14 17:24:04 | https://cdn.sql.gg/O3qi9_BhkjmdcZSJTRrQXwKlqiCk... | Offline | 32 exe RedLineStealer | |
| 2021-10-14 17:24:03 | https://cdn.sql.gg/p57rynRvkn5v9eGuJELbosNasZQe... | Offline | 32 AveMariaRAT | |
| 2021-10-12 16:51:07 | https://cdn.sql.gg/qXrsGocSM5NfC34qv31bzIT0a7Om... | Offline | RedLine | Anonymous |
| 2021-10-11 06:31:09 | https://cdn.sql.gg/trgm23WNvBZeJgU9_UeZdkeRr0pz... | Offline | 32 AsyncRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-10-14 17:31:15 | 99132457ab16ed22ad2581ad07c1f4bbd07c4adcb12e39e74df9d150f13c84b7 | exe | AveMariaRAT | |
| 2021-10-14 17:24:04 | 5d5a4e577c7e58c88e50a4c6553943a861ed52728255a3f549ab02d673853a70 | exe | RedLineStealer | |
| 2021-10-12 16:51:06 | 73b3e0381a352a66aeccf2f3b87fd13273f93a69678f75d08a3e41b8ebec339e | unknown | ||
| 2021-10-11 06:31:09 | b11e3001340981c07bfba49edb915ffb4a8f599af6991179ea5d81a79a29c7fa | exe | AsyncRAT |
RU