URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-07-16 13:31:02 | 34.94.114.14 | 14.114.94.34.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | yes |
| 2022-06-27 20:18:06 | 34.174.95.150 | 150.95.174.34.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-06-27 20:18:06 | http://judithabusufaitdyg.duckdns.org/winupdate... | Offline | 32 exe LimeRAT Loda |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-07-19 04:26:29 | 15504193354c906ed2079878c0c104e3e420d887c5c5ab9fabed3d60afdb3bbc | exe | LimeRAT | |
| 2022-07-13 01:16:59 | 064c82c9caf9d7ac84081f1a3e7db2f8b53fe0b63b42f950700305cfb61912ac | exe | Neshta | |
| 2022-07-12 06:29:28 | affe23699997f46b33a4f43d8558d7ec89603460ecea2f98952527dbaf09288f | exe | Loda | |
| 2022-07-08 00:05:11 | 9a125f79e4303e975d546b95d2fc83736bdd38fdfb18f6e1a3f2d76c16458d1e | exe | ||
| 2022-07-07 15:03:54 | d7580616774e8f0697b8f3b138ed40ce7390f33e9b69b0ea0f0c4ce27726cdb1 | exe | ||
| 2022-07-06 15:05:34 | cd6a8e6b17a1ecb5aafb24ef4f7ec0ba0be44508ea10dbde551e0037220571f8 | exe | RedLineStealer | |
| 2022-06-27 20:18:06 | 78d88a6ac29625636a7433e358459a8cdfb837c853f6a149ceea102e707997f3 | exe | RedLineStealer |

US