URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 17:17:57 | 208.91.197.27 | Not listed | AS40034 CONFLUENCE-NETWORK-INC | VG | yes | |
| 2020-04-16 18:42:11 | 198.72.96.174 | secure.securehost.us | Not listed | AS32613 IWEB-AS | CA | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-04-21 18:42:33 | https://gulfcrossings.com/sport/rockstar.php | Offline | exe IcedID | |
| 2020-04-16 18:42:11 | https://gulfcrossings.com/yas28.dll | Offline | dll Trickbot |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-04-21 19:48:19 | c558e5dbe147aa6764e52188ad206cf2b82ab6c1cc1195b30f8f3280d7aabc78 | exe | IcedID | |
| 2020-04-21 19:30:41 | 864fc7bef58b26ae9c4bce8caf782d5e94c57080858906047bba6a5ac2004769 | exe | IcedID | |
| 2020-04-21 19:10:02 | da96c0f0f88329aeb70e4b7a487eb76e5210aa352a0288ff6581c0a7a013915f | exe | IcedID | |
| 2020-04-16 18:42:11 | 25ac7e0410299ac6572befc8784420ecbc829ab0db38a7eb46a83855b419212f | exe | TrickBot |
VG
CA