URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-14 11:36:48 | 38.14.42.40 | Not listed | AS398823 PEG-LA | US | yes | |
| 2021-12-20 22:59:10 | 149.56.163.161 | Not listed | AS16276 OVH | CA | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-07-01 19:28:04 | 1a41ee03641f4a0f8012ddfbc018b9099e1b52cc5625b6a6b0fcc6234a822fe0 | dll | Heodo | |
| 2022-02-10 11:48:43 | f46e1a108b368dd1063f1a0577a927407562480d331baab3e25d9c119f841dff | hta |

CA