URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-07-31 04:33:54 | 37.119.171.146 | net-37-119-171-146.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-05-13 12:18:43 | 2.45.248.130 | net-2-45-248-130.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-04-13 21:27:00 | 5.95.41.119 | net-5-95-41-119.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-03-02 18:02:51 | 5.89.185.42 | net-5-89-185-42.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-02-26 12:50:54 | 5.88.124.112 | net-5-88-124-112.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-02-21 13:29:36 | 2.44.186.53 | net-2-44-186-53.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-01-30 05:35:28 | 37.183.240.79 | Not listed | AS30722 VODAFONE-IT-ASN | IT | no | |
| 2025-01-25 18:42:21 | 37.183.212.114 | Not listed | AS30722 VODAFONE-IT-ASN | IT | no | |
| 2025-01-17 23:20:02 | 5.95.238.77 | net-5-95-238-77.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
| 2025-01-12 13:41:02 | 2.45.248.38 | net-2-45-248-38.cust.vodafonedsl.it | Not listed | AS30722 VODAFONE-IT-ASN | IT | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2024-12-31 07:35:29 | http://jholo.duckdns.org:8181/PASSWORDRECOVERY6... | Offline | DarkVisionRAT | |
| 2024-12-31 07:35:14 | http://jholo.duckdns.org:8181/upload.php | Offline |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-12-31 07:35:28 | 98e9562d0d6914509132a5b8895ab6686798e10e56fe3347f75155d48f3e8d6c | exe |

IT