URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 00:33:27 | 49.13.11.35 | static.35.11.13.49.clients.your-server.de | Not listed | AS24940 HETZNER-AS | DE | yes |
| 2021-05-03 13:00:04 | 78.47.142.185 | static.185.142.47.78.clients.your-server.de | Not listed | AS24940 HETZNER-AS | DE | no |
| 2021-05-07 21:39:53 | 93.89.226.17 | 93-89-226-17.fbs.com.tr | Not listed | AS51557 TR-ISIMTESCIL-20201202 | TR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-05-04 10:17:05 | http://citycardriving.net/zone/flexing.exe | Offline | exe NanoCore | |
| 2021-05-03 14:48:10 | http://citycardriving.net/thet/fixxing.exe | Offline | exe NanoCore | |
| 2021-05-03 13:00:04 | http://citycardriving.net/filz/note-mxm.exe | Offline | NanoCore |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-05-04 10:17:04 | 98d330aee7d8bec5bccddb1a9c2fd2963c8a8dce01df1936be495e3c14d2ec77 | exe | NanoCore | |
| 2021-05-03 14:48:10 | 91f6fc2ae99e090dad56e53c7bf258dd4f43df79ac02a11f2620c31f045fc87f | exe | NanoCore | |
| 2021-05-03 13:00:04 | 43bc7ada65633263e408152d7b117de464c9d23b2758d96a6822bde9ad27b170 | exe | NanoCore |
DE
TR