URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-10-15 04:01:53 | 104.21.28.217 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-10-15 04:01:53 | 172.67.147.181 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2023-06-13 15:04:10 | 108.167.188.16 | br352-ip04.hostgator.com.br | Not listed | AS19871 NETWORK-SOLUTIONS-HOSTING | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-06-13 16:37:15 | https://ctnano.org/ms/?1 | Offline | BB32 geofenced js Qakbot | |
| 2023-06-13 15:04:10 | https://ctnano.org/ms/ | Offline | BB32 PDF Qakbot |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-06-14 01:57:43 | 52029a2f5051ca1ea16887ce8a453cf92970b3b1b828ef9c388b4e4aed6649bf | js | Quakbot | |
| 2023-06-14 00:05:33 | 9ea92b344586ead491a8abfffa283432b9119fdd13d753e83e5dd55465d0970f | js | Quakbot | |
| 2023-06-13 22:38:40 | 56ad902e1244e7faba3b1892053da477ef3d9a67ac930c17573b512fa11d5e36 | js | ||
| 2023-06-13 21:58:15 | fdef38221e0225e6501b9bc784617eae4b6eab280721139c1618383cb3f0a6f8 | js | Quakbot | |
| 2023-06-13 20:38:29 | 0c21520790a4f916213684fcdd904aea5ce48528eb25843c7eafd8c9bd706f3e | js | Quakbot | |
| 2023-06-13 18:55:34 | be8bda9b2381310721ec9c6984328de60aba2660ca5c45193af121363547cae1 | js | Quakbot | |
| 2023-06-13 18:16:18 | 0684acd526508b790a60181d02639f52f36ee2b2c149082a58d7a956a4a8ab98 | js | Quakbot | |
| 2023-06-13 17:37:41 | 5cc2407f2c235a200e72823f12a4ef6b93f123c76b2887a7acab26068504e706 | js | Quakbot | |
| 2023-06-13 16:37:14 | d03f71f159f250cce009313d83a25715434e8bb68b235fefe01a1116f20ba499 | js | Quakbot |
