URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2020-05-17 18:47:43 | 128.199.253.44 | ns337.naxza.com | Not listed | AS14061 DIGITALOCEAN-ASN | SG | yes |
| 2020-01-30 07:34:43 | 122.155.1.69 | ns145.naxza.com | Not listed | AS9335 cat-Cloud-AP | TH | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-11-27 08:10:52 | http://khunnapap.com/inc/lxpo.exe | Offline | ModiLoader | |
| 2020-10-07 14:01:16 | http://khunnapap.com/js/vic2.exe | Offline | Formbook | |
| 2020-01-30 10:48:12 | http://khunnapap.com/js/moment/fern.exe | Offline | AgentTesla | |
| 2020-01-30 07:34:43 | http://khunnapap.com/js/images/fme.exe | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-11-27 08:10:52 | 344ca08fa2fdb87931ceb1e336019231bfba189458be0d3fa5016b5895d96cc6 | exe | ModiLoader | |
| 2020-10-07 14:01:16 | 82b0bf0df7b8987197d19071dfda32b037ee3251291b08f6d979749635784e89 | exe | Formbook | |
| 2020-05-02 23:31:33 | c90f4d6a1a0598c9a0ba79a74f0a1f68f50f85a4b7b488e72bad4ae8e4dcc221 | exe | ||
| 2020-04-08 20:02:01 | 1e20c271421f92b59b55d6c430a61009db4fc908fe295d044868515e4ae76e89 | exe | ||
| 2020-03-07 01:09:34 | c7ffc9f6112f072bf1a06194ca6fa1623f68a928529dc958c426f0616cd61421 | exe | ||
| 2020-01-30 10:48:12 | e02aed1544c351c39b691a9464f6954ed7d078743faa127f379912b8e1829863 | exe | AgentTesla | |
| 2020-01-30 07:34:43 | 7d6bcf00527e834dae98ca91539b4313949e016281756fc33c404bb3b758deb5 | exe | AgentTesla |
SG
TH