URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-07-23 15:55:29 | 216.198.79.1 | 216-198-79-1.client.cypresscom.net | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-07-21 13:21:05 | 64.29.17.1 | Not listed | AS16509 AMAZON-02 | US | yes | |
| 2025-07-21 13:21:05 | 216.198.79.65 | atl-cer1-755commercedr.cypresscom.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-07-24 10:41:41 | 64.29.17.65 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2025-04-27 17:57:28 | 84.16.234.51 | host21.server.ae | Not listed | AS28753 LEASEWEB-DE-FRA-10 | DE | no |
| 2023-02-22 18:37:17 | 84.16.234.35 | host23.server.ae | Not listed | AS28753 LEASEWEB-DE-FRA-10 | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-02-24 01:18:06 | https://hayainteriors.com/svcrun.exe | Offline | CoinMiner exe | |
| 2023-02-22 18:37:17 | http://hayainteriors.com/svcrun.exe | Offline | dropped-by-PrivateLoader |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-02-24 01:18:06 | fa1a3d581f285e49916ae65313639b598e84715e6bef215d492f21c163490e10 | exe | CoinMiner |
US
DE