URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-08-17 12:26:44 | 31.43.160.6 | sites.framer.app | Not listed | AS16509 AMAZON-02 | NL | yes |
| 2025-08-17 12:26:44 | 31.43.161.6 | sites.framer.app | Not listed | AS16509 AMAZON-02 | NL | yes |
| 2022-10-14 02:49:12 | 67.222.38.76 | box2044.bluehost.com | Not listed | AS46606 UNIFIEDLAYER-AS-1 | US | no |
| 2023-01-29 05:54:54 | 188.114.96.3 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-01-29 05:54:54 | 188.114.97.3 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2022-10-23 17:55:20 | 66.235.200.146 | host77.ipowerweb.com | Not listed | AS13335 CLOUDFLARENET | US | no |
| 2022-11-10 20:31:24 | 104.21.35.144 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2022-11-10 20:31:24 | 172.67.175.188 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-01-31 01:07:51 | 188.114.96.9 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-01-31 01:07:51 | 188.114.97.9 | Not listed | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-10-14 04:41:10 | https://il-designs.com/z2.exe | Offline | 32 ArkeiStealer | |
| 2022-10-14 02:49:13 | https://il-designs.com/jamesp.exe | Offline | 32 exe RedLineStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-10-14 04:41:10 | dc603e5b83b3707a92b34f8d76c08fa494d6684080be06bd59111ea28f26188b | exe | ArkeiStealer | |
| 2022-10-14 02:49:12 | 823bd4fcdfdb81a51c49177d8847253304a78a4829cad948ac0be21df083cc94 | exe | RedLineStealer |

NL