URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-02-11 09:05:42 | 91.227.16.6 | pxe1.host-food.ru | Not listed | AS207027 Eximius-AS | RU | yes |
| 2022-12-26 17:05:13 | 91.227.16.12 | srv12.host-food.ru | Not listed | AS207027 Eximius-AS | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-01-08 16:31:12 | http://h166578.srv12.test-hf.su/31.exe | Offline | eternitystealer | |
| 2023-01-06 09:39:10 | http://h166578.srv12.test-hf.su/28.exe | Offline | ArkeiStealer | |
| 2023-01-05 07:09:04 | http://h166578.srv12.test-hf.su/27.exe | Offline | exe RedLineStealer | |
| 2022-12-31 10:37:10 | http://h166578.srv12.test-hf.su/25.exe | Offline | ArkeiStealer | |
| 2022-12-28 20:20:12 | http://h166578.srv12.test-hf.su/21.exe | Offline | cutwail | |
| 2022-12-28 20:19:05 | http://h166578.srv12.test-hf.su/20.exe | Offline | dcrat exe | |
| 2022-12-26 17:05:13 | http://h166578.srv12.test-hf.su/19.exe | Offline | exe PandaStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-01-08 16:31:12 | 90ac709312ca3f366e138a84bb93d453544fc227d525fbef47b4d7a90ac6f820 | exe | EternityStealer | |
| 2023-01-06 09:39:10 | 32248f0553821820bdb2a1d5a8346f16ddc53c041a1e57758479bd3a73e8e65e | exe | ArkeiStealer | |
| 2023-01-05 07:09:04 | 30e0aa68e3248e80101473ca6f1158dd93b4e1aba1e487d35f6cb2d666973e56 | exe | RedLineStealer | |
| 2022-12-31 10:37:10 | a14600c06ba898ae24152bfdc01c6c514007dec5d81d95161f5fdb3e6399adc0 | exe | ArkeiStealer | |
| 2022-12-28 20:20:12 | 8e35b5b98aed8865cf0d19f56d458415ddb62112d88802d8d0cdee9bf88aa7f5 | exe | Cutwail | |
| 2022-12-28 20:19:05 | 3aa5ddb2f7d544c1a52d73ce4086118ca8b053cf5ef38bb07287d8e7782218fb | exe | DCRat | |
| 2022-12-26 17:05:13 | 39d3801ccfbeb255a58b591edb846b38e5efef1cd36e0aba54fec3d164e8d795 | exe | PandaStealer |
RU