URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 15:21:53 | 128.65.195.252 | h2web236.infomaniak.ch | Not listed | AS29222 Infomaniak-AS | CH | yes |
| 2020-06-08 01:28:35 | 213.186.33.40 | cluster011.ovh.net | Not listed | AS16276 OVH | FR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-06-08 01:29:46 | http://guidetti.ch/libraries/src/Plugin/z.exe | Offline | exe | |
| 2020-06-08 01:29:08 | http://guidetti.ch/libraries/src/Plugin/Quc.exe | Offline | exe QuasarRAT | |
| 2020-06-08 01:28:35 | http://guidetti.ch/libraries/src/Plugin/ASss.exe | Offline | exe |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-06-08 01:29:46 | fdd5cb1aa6a4332b83e5a68add9b6333009431e102d93785d0c0a8238e744d6d | exe | ||
| 2020-06-08 01:29:08 | 6a4858fcec3ea47bf1371d81f4fc10010c541c277cc0fa19d3f43bfab0a4bcb1 | exe | QuasarRAT | |
| 2020-06-08 01:28:35 | 5b2b90c67644c5200ca7e5e579cbae14435a707cdb72c687a2ff9b18d0e6a13a | exe |
CH
FR