URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2021-06-21 16:44:42 | 103.85.74.92 | Not listed | AS152320 GOALNOW-AS-AP | HK | no | |
| 2021-05-14 19:43:12 | 34.98.99.30 | 30.99.98.34.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | no |
| 2020-11-12 19:21:03 | 109.234.164.75 | 109-234-164-75.reverse.odns.fr | Not listed | AS50474 O2SWITCH | FR | no |
| 2021-06-20 16:31:31 | 34.102.136.180 | 180.136.102.34.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-11-12 19:24:03 | http://justburrgrinder.com/in/statement.exe | Offline | exe | |
| 2020-11-12 19:21:03 | http://justburrgrinder.com/in/SN20201012002.exe | Offline | avemaria |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-11-12 19:24:28 | 19f8b1a5194081fc8e0649560e296547554b5f6f3102e096eb8e1f015138f7b1 | exe | AveMariaRAT | |
| 2020-11-12 19:24:03 | d3c11799a78a537079dc50537897ed856096da2455d1e877862c724e67dd1d9c | exe |
HK
US
FR