URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-02 07:49:39 | 104.21.26.184 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-11-02 07:49:39 | 172.67.138.88 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2020-11-18 12:14:20 | 208.91.199.91 | bh-13.webhostbox.net | Not listed | AS46606 UNIFIEDLAYER-AS-1 | US | no |
| 2025-05-03 21:41:37 | 165.227.147.29 | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no | |
| 2020-12-17 00:00:31 | 198.211.125.132 | Not listed | AS14061 DIGITALOCEAN-ASN | NL | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-11-18 12:14:20 | http://e-kconsulting.co.ke/gv9zl1mso.txt | Offline | dll Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-11-19 07:28:15 | 69b8edabcaa280d39bfab15c7d12e8aef75d94090ece29a9b074bdef2906fa25 | dll | Dridex | |
| 2020-11-19 04:27:08 | 083a0a9224164d091360e1888a7cd2baa0f496b28be420ffdcfa293530c445cd | dll | Dridex | |
| 2020-11-18 18:08:09 | 581a2419d8e96d3367e5ead5f7de2c743133db0e69e6f3721d4a99c9ebafda36 | dll | Dridex | |
| 2020-11-18 16:25:05 | a6dd0ab287f5ec1861244476be86389947ebc9539c7730c09ee9b679c48ba798 | dll | Dridex | |
| 2020-11-18 15:11:35 | 0dfab637891eaf6ff9134a21c5200d677f6e915a25b43e8a4acc5fe90f793033 | dll | Dridex | |
| 2020-11-18 13:51:36 | f051d9f61ef1f401ae946ad290128df9772cd030fce4fe289037b650906c9ded | dll | Dridex | |
| 2020-11-18 12:14:19 | f4e65ecea469214769a863058823613437eb066a0baf40b5f9342958fce1e7a7 | dll | Dridex |
US
DE
NL