URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-11-02 17:46:04 | 208.91.197.13 | Not listed | AS40034 CONFLUENCE-NETWORK-INC | VG | no | |
| 2023-10-01 20:30:19 | 108.179.232.106 | grand-eksport.gfc.mk | Not listed | AS19871 NETWORK-SOLUTIONS-HOSTING | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-10-11 09:29:04 | http://enfantfoundation.com/amday.exe | Offline | Amadey | Anonymous |
| 2023-10-01 20:30:19 | http://enfantfoundation.com/netTime.exe | Offline | CoinMiner dropped-by-PrivateLoader Phonk |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-10-11 10:36:52 | 3af504bff6826b81d0093b8d153643afb6e86d78db4dfc2cb6f9574ea14265d4 | exe | Amadey | |
| 2023-10-06 19:00:24 | 1f87cc53b65d230d000fb5332e3d13a01bae16ed20c81656f5dc30a440daaf84 | exe | CoinMiner | |
| 2023-10-04 14:22:27 | 92b9dbef2c0414a2e5f09e2a419a80ba9feb628761a6b07d14fb885b2fa22b60 | exe | Phonk | |
| 2023-10-03 07:17:26 | 343ed81c3b97f9cff2d0ae5fe734dd1849d4d0fd3dd3887cde9ca4186ef91a47 | exe | Phonk | |
| 2023-10-02 14:25:12 | d273d63ec7562e27003ad53db329429452d86faef87b6d64b72875cdb1dd3cee | exe | Phonk | |
| 2023-10-01 20:30:19 | 402f8ae71cdd4c4a8ddcbeb123879824d9c40bd6d8c8d04f1e6575c049105eea | exe | CoinMiner |

VG