URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-02-26 08:05:07 | 104.21.80.1 | SBL681411 | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.112.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.32.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.48.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.64.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.16.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-02-26 08:05:07 | 104.21.96.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-02-26 08:36:06 | https://korvewo.top/tOOifSdzE7c9dXR.scr | Offline | exe MassLogger | |
| 2025-02-26 08:36:06 | https://korvewo.top/cryptedprosp.exe | Offline | exe MassLogger | |
| 2025-02-26 08:36:04 | https://korvewo.top/jKuil2m4oIniPNC.exe | Offline | exe MassLogger | |
| 2025-02-26 08:36:04 | https://korvewo.top/osfile01.exe | Offline | exe MassLogger | |
| 2025-02-26 08:36:04 | https://korvewo.top/4KKi8Zrv9nyAmhR.exe | Offline | exe MassLogger | |
| 2025-02-26 08:05:07 | https://korvewo.top/file_1.exe | Offline | exe Loki |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-02-27 06:05:38 | b3a93777cd6c432b97a3fc5257034746cd5a8b0db244a9e071bdc6d35f0d405f | exe | MassLogger | |
| 2025-02-26 08:36:06 | 572ee11cb26d0952d901bc35f226d46264264f01afa9cc1491745400f5e5f360 | exe | MassLogger | |
| 2025-02-26 08:36:06 | 39bfc41b1b43a5319ca1c0b1df4906b2ff41c120223f372e85a696432667fd93 | exe | MassLogger | |
| 2025-02-26 08:36:04 | fbaec035008b4d3722c9b832c534d85660e7c80027a29d1d8310b77b2ad54fc7 | exe | MassLogger | |
| 2025-02-26 08:36:04 | 42b1c4d3e4813837cd0e171e23cc140d8f65ea6581dd443f106269e6acbc00c1 | exe | MassLogger | |
| 2025-02-26 08:36:04 | 8bf01e5c0e48ae7f101d2e955f9829fa545449488b22d5bc1d02fc56545cb27e | exe | MassLogger | |
| 2025-02-26 08:05:07 | d50ab4d8ad2b28638f61bb58b16ead8880c73fd288aa894d9badb125d6559352 | exe | Loki |