URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-10-29 23:22:49 | 185.93.2.243 | 185-93-2-243.bunnyinfra.net | Not listed | AS60068 CDN77 | FR | no |
| 2022-10-22 06:37:12 | 143.244.38.137 | 143-244-38-137.bunnyinfra.net | Not listed | AS60068 CDN77 | GB | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-10-22 06:37:12 | http://gfhj.b-cdn.net/chrome.exe | Offline | exe | |
| 2022-10-22 06:37:12 | http://gfhj.b-cdn.net/brave3.exe | Offline | CoinMiner exe | |
| 2022-10-22 06:37:12 | http://gfhj.b-cdn.net/brave.exe | Offline | CoinMiner exe | |
| 2022-10-22 06:37:12 | http://gfhj.b-cdn.net/brave2.exe | Offline | CoinMiner exe |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-11-04 01:04:17 | 054174b77c43d2b1a97a1238282818dc2792535ec0e3b94102c58d9d9ffeba15 | exe | CoinMiner | |
| 2022-10-22 06:37:12 | c832fe9f9a39541e3e1ba09c0b2c143d639c235f3634db05b487cb9518779506 | exe | CoinMiner | |
| 2022-10-22 06:37:12 | c009d0c4e76cf1bdf126d14c3b82897bbcc2e920af79e7286ffd1c6e737491ec | exe | CoinMiner | |
| 2022-10-22 06:37:12 | c009d0c4e76cf1bdf126d14c3b82897bbcc2e920af79e7286ffd1c6e737491ec | exe | CoinMiner | |
| 2022-10-22 06:37:11 | e1def500e52c2191fa3094f3dc69bc77ab4cd7d1ac73338f2a93c86339b29f8e | exe |

FR
GB