URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-12-04 01:18:10 | 91.227.16.6 | pxe1.host-food.ru | Not listed | AS207027 Eximius-AS | RU | yes |
| 2022-10-20 13:14:10 | 91.227.16.11 | srv11.host-food.ru | Not listed | AS207027 Eximius-AS | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-10-28 06:10:12 | http://h165621.srv11.test-hf.su/200.exe | Offline | exe | |
| 2022-10-28 06:10:08 | http://h165621.srv11.test-hf.su/199.exe | Offline | exe RedLineStealer | |
| 2022-10-24 07:58:06 | http://h165621.srv11.test-hf.su/198.exe | Offline | cutwail | |
| 2022-10-22 06:35:14 | http://h165621.srv11.test-hf.su/197.exe | Offline | exe gcleaner | |
| 2022-10-20 13:14:11 | http://h165621.srv11.test-hf.su/194.exe | Offline | exe | |
| 2022-10-20 13:14:10 | http://h165621.srv11.test-hf.su/195.exe | Offline | exe gcleaner |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-10-28 06:10:11 | e9e0d434434317280e474dedd4a72f60a9136153acea4d8e8ac64d77ddc25b38 | exe | CMSBrute | |
| 2022-10-28 06:10:08 | bf4defa19f39c56ce003b1e7afea73c99554742f56b48dca2eb52a135d8cf0a5 | exe | RedLineStealer | |
| 2022-10-24 07:58:06 | 74b4a1409e686d9b8743ba282776b5498084cd4cecc1e10f1d2fde3ee5f3f401 | exe | Cutwail | |
| 2022-10-22 06:35:13 | 932d7ae8482eee2509bdecb13ad9f11c4ad3441b4a149e514a78f0553c5c7fc4 | exe | GCleaner | |
| 2022-10-20 13:14:10 | de0ea6b286c73aef00f5bb96a5469160360e09848708e6537e260007e85456bb | exe | GCleaner | |
| 2022-10-20 13:14:10 | 4908395a56a5c48373993a6b6eea963810804c123e54e1f80a7c94c1202d6fb9 | exe | CMSBrute |
