URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-05-21 22:30:29 | 91.227.16.6 | pxe1.host-food.ru | Not listed | AS207027 Eximius-AS | RU | yes |
| 2023-04-15 15:39:05 | 91.227.16.22 | srv22.host-food.ru | Not listed | AS207027 Eximius-AS | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-04-19 16:05:14 | http://h168476.srv22.test-hf.su/119.exe | Offline | exe RedLineStealer | |
| 2023-04-15 15:39:07 | http://h168476.srv22.test-hf.su/114.exe | Offline | exe RedLineStealer | |
| 2023-04-15 15:39:05 | http://h168476.srv22.test-hf.su/113.exe | Offline | cryptbot exe | |
| 2023-04-15 15:39:05 | http://h168476.srv22.test-hf.su/115.exe | Offline | exe RedLineStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-04-19 16:05:14 | 28571927ef1ac3a554f4933953e9089167d0f896c78e8a7abf34bddd541f641f | exe | RedLineStealer | |
| 2023-04-18 21:22:50 | f3959e218851d141f19a4b5bf89ef22e83d5b5a67bea6457f3d3e217bef8b0a3 | exe | RedLineStealer | |
| 2023-04-18 13:22:36 | 84219f88f776f0847bf602e1a18f795c235f641d04b934248eb27f65335f502d | exe | RedLineStealer | |
| 2023-04-18 00:00:17 | a29bd0ca695fbaf70cf52a2ea79127d888377de686c4d3c52967517cae80191e | exe | RedLineStealer | |
| 2023-04-16 20:23:54 | b74cd95e44eec9e71e9042bf98030fe8929332bc29f8e0cd969c7e4ccc2ecec2 | exe | RedLineStealer | |
| 2023-04-15 15:39:07 | eb070fb1f4a7b4c38f28b71b4ddd4127e839fbb960c471a51f299ef78d7eed87 | exe | RedLineStealer | |
| 2023-04-15 15:39:05 | 574afcec719331221014fefc45e623e57ff81468b21fcbc186fa7f448be48a40 | exe | CryptBot | |
| 2023-04-15 15:39:05 | 9f7b850b2f255a609532c8bac161f2c11dca15133312cb2a3f7a989eca325969 | exe | RedLineStealer |
