URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: coltec.ga
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-28 08:05:33 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)
A record(s) observed :44

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-09 23:48:34 161.117.224.167Not listedAS45102 ALIBABA-CN-NET- SGno
2020-10-08 11:05:17 119.28.232.76Not listedAS132203 TENCENT-NET-AP-CN- KRno
2020-10-07 10:25:58 119.28.154.24Not listedAS132203 TENCENT-NET-AP-CN- KRno
2020-10-06 08:21:31 150.109.244.206Not listedAS132203 TENCENT-NET-AP-CN- KRno
2020-09-28 16:14:01 18.221.107.58ec2-18-221-107-58.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2020-09-25 00:01:41 176.118.165.206Not listedAS43830 DIGITALENERGY-AS- RUno
2020-09-16 09:54:56 85.143.172.11085-143-172-110.simplecloud.ruNot listedAS201848 TRADERSOFT- RUno
2020-09-15 09:38:02 176.118.165.145Not listedAS43830 DIGITALENERGY-AS- RUno
2020-09-14 11:11:03 176.118.165.208Not listedAS43830 DIGITALENERGY-AS- RUno
2020-09-14 08:21:07 176.118.165.162Not listedAS43830 DIGITALENERGY-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-08 06:13:07http://coltec.ga/%7Ezadmin/temp/0ap.exeOfflineexe Formbook ext Loki ext oppimaniac
2020-10-01 20:49:38http://coltec.ga/~zadmin/temp/0ha.exeOfflineexe Loki ext abuse_ch
2020-08-31 05:24:07http://coltec.ga/~zadmin/dwld/none.exeOfflinebitrat ext exe abuse_ch
2020-08-28 09:06:15http://coltec.ga/~zadmin/temp/0pm.exeOfflineexe Pony ext zbetcheckin
2020-08-28 09:03:13http://coltec.ga/~zadmin/temp/0ap.exeOfflineexe Formbook ext Loki ext zbetcheckin
2020-08-28 08:05:35http://coltec.ga/~zadmin/temp/0bil.exeOfflineexe Loki ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-08 22:57:09cafbf0ca3d9697de117f1f5f4bbaa1a2717fc7b8485a492b9eac2def9632f52cexeLoki
2020-10-08 22:53:16cafbf0ca3d9697de117f1f5f4bbaa1a2717fc7b8485a492b9eac2def9632f52cexeLoki
2020-10-08 22:47:328e638a6ae4c931027d94b5e71c3b6c4a066ece89b0ab087510866d6110f793ebexeLoki
2020-10-08 06:13:07ebd88634ecfbdc7e88bca32a0b22fa35e24c9feb309799128f3d12d2cceac224exeFormbook
2020-10-07 20:58:4002416b53e5d525df526843451805a9c87920ddb34ca23c5fb5b59b34b56a7f82exeLoki
2020-10-07 20:45:21ebd88634ecfbdc7e88bca32a0b22fa35e24c9feb309799128f3d12d2cceac224exeFormbook
2020-10-06 21:30:506f6fc5091118c3a8442970c1f3a3a103dcf5f2758021cc673d440beba025c25cexeLoki
2020-10-06 21:11:350aa79342c00ecadc1a8771b574911abbc7bd89d833598ea1bf9ad7ffa63c2ee9exeLoki
2020-10-06 00:32:263e32845eeb74c41195c5ecdbb053ae6a29ec8b66dedac32ddd625ac8d4913facexeLoki
2020-10-05 21:06:42df8b425e4f5ce5faef299b2f83aabdc9a1d9f2d28be9aaf4e41215488820c0d9exeLoki
2020-10-04 20:21:491c44b1e0a3f3186e814a13d4cd895bb1de20cbb343f6ec3b56908868998791f6exeLoki
2020-10-02 02:03:47f457caeb3fedec72b6d8ab1b6bfcf3cdb11e0c4cf07dee53f659c1e24de7f733exeLoki
2020-10-02 02:00:0037b3fa9a0fad103ba7311948f3eff98779253409556488638ffe057e435d812dexeLoki
2020-10-01 20:49:38aa870e1218a74e244dbe047277a2037c22c4460cb5ebfc5d12267950121bad6fexeLoki
2020-10-01 00:32:42b1a522cf1688c79e5148c41caa7ebf9c71f9cb0a87e3d2c3acd4a0e5f9c22705exeLoki
2020-09-30 01:51:012652463d20fd9db97f8149be519413cae87b846986d1eb4784fd886af8b9f977exe Loki
2020-09-29 00:06:087b59aa7d23a9ea86c5a12bad49cc727909ff58a2d3e8d2bc242ca3eb1b9350ebexe Loki
2020-09-24 22:10:464eb8bed8591422f6065c3198d6c3464b14e438f6566003997d98b81d776f02b9exeLoki
2020-09-23 22:56:24103b80a529ef18579c7078a3889d0d8262848d29cf7ddcf16faf83ec350f7c63exe Loki
2020-09-22 21:30:551d70d8d0e34fb9df8625c040957a124f0fec9cc14902824293b8a64ebf23911bexe Loki
2020-09-22 01:55:256012333b74487f614be5cf6b2af70106279461283fc9c3232bd7d5a5bb8e87dfexe Loki
2020-09-22 00:53:33ae08212f92cff9784dcf5aa675e51122bf9a0542be9bda43d731d64b032a2b37exe Adware.Generic
2020-09-21 03:02:41c62416f0cd57c70638383e4a97bb2aab0e457209e8b782978bc6eb110b7a92c7exe Loki
2020-09-20 22:47:4218d42895a0a37161199e0f3da093cb3057f71a608866a3d3284c83a7b90dbf81exeFormBook
2020-09-20 21:55:2681de431987304676134138705fc1c21188ad7f27edf6b77a6551aa693194485eexe  
2020-09-18 00:21:50fca32cf0c62210488d4c092cb9e44b7089b661f7419f3c8a56c4f21a02991b4eexeLoki
2020-09-16 23:41:3814b23833a0069ece9c114d554b406c7f1da45fdcd910ecee37fbf0136aa09af2exeLoki
2020-09-15 22:41:22ce25afb958b5ae70651c279cc541d045d0531b1a3eb97ba7bf0a065e40828082exe Loki
2020-09-15 00:07:52ec445f889b5b9541628dfd3c7492ac329c978c7b7088fdeb81002646afabd64dexe FormBook
2020-09-13 23:08:29414578aa9e1ab74c43ae636f64758a5a2dd59ab81619aa054de1fb6c9140f2e6exeFormBook
2020-09-10 23:41:0501da092bc20b08ea1bea6de68bc460606e7c34254de25501d0c4f385eb02e6bbexeLoki
2020-09-09 21:28:197c18464e0b9693a7f701815d1a767074fe452a84eb0636bcbcf7f374fe08847cexeLoki
2020-09-07 19:55:1772ec3dcd3d7a197c45c66605330968f86044d6a2ec37bf843e33b7f4668781f9exeAdware.Generic
2020-09-03 23:40:5446c00c94bffc91316d10ed011e9d8168bc4e9c4416387427367005cd632452feexeLoki
2020-09-03 07:33:094256cb27af8d8b2cdde631191db4a1ea1c5054fd21e7e1ed5fb94f8f65d6f32bexe Loki
2020-09-03 07:31:221842672695dadd66cab17c68e9539c75a48268fd5ed7bd1cb8eab24457a88540exe Downloader.Pony
2020-09-03 07:27:16948e6e5867d676b1c1a3844a8e012d6169dab72638ecc6d199f416663f04c4bcexeLoki
2020-08-31 05:24:0794baaa6950d843af8b93d7705cb5b38cb4df644d76f4faccb305bed112845a5bexe BitRAT
2020-08-30 20:05:079dc88dec4a1a8fab1526dd1a856542e011b7ad5a62ec049c07d0eca58843a9f0exeLoki
2020-08-28 09:06:15a82e6492b049410650e0283c886c096ef0169996c8a2405d7114824b3fa2475bexe Downloader.Pony
2020-08-28 09:03:131333a1f4e72776e3a6e006488980735994ec62a0a23538d78c5962c323e84562exe FormBook
2020-08-28 08:05:35af0b475ef7baf7f3c161143fc00a7f0b5ae427feb41cd796cd0b232764dba0d3exe Loki