URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2020-10-20 04:47:13 | 196.41.123.124 | cpanel13.mywebserver.co.za | Not listed | AS36874 Cybersmart | ZA | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-10-20 04:47:13 | https://kriya.co.za/cgi-bin/GgSkXPb/ | Offline | emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-10-20 07:04:23 | 30d1d3265a91a06771060a28147a68389bf55baaba58735528fb3dbfa7256f30 | exe | Heodo | |
| 2020-10-20 06:45:37 | 248f2403a3e73728663b4264922cdef1adf5d2d585ec39d7488e7c81682f375f | exe | Heodo | |
| 2020-10-20 06:23:12 | 7c7331198e83afdbc51a0eb165be9ad3b560469698525f7dcded807a9a38b13a | exe | Heodo | |
| 2020-10-20 06:01:34 | 7f1f39d51f79bc782424abc3567c075a6df0d84d9b4c57bb8ec2668b9ab38f35 | exe | Heodo | |
| 2020-10-20 05:35:41 | d47b03c72c72d460fbb39a03b3c7a8e5da4820b60863757d2d340e681bef8e73 | exe | Heodo | |
| 2020-10-20 05:08:07 | b5cb4112c9423ad6fd85719ee99f857e94c0e7ee405fcde7f52997c793ab7fdd | exe | Heodo | |
| 2020-10-20 04:47:12 | 3adc6c62554974a010dafcd26ce231bb96b47f1941b8004de933276742b65ff8 | exe | Heodo |
ZA