URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-30 06:27:26 | 5.78.76.118 | static.118.76.78.5.clients.your-server.de | Not listed | AS212317 HETZNER-CLOUD3-AS | US | no |
| 2021-04-17 08:53:26 | 143.198.60.155 | Not listed | AS14061 DIGITALOCEAN-ASN | US | no | |
| 2020-10-20 15:48:07 | 198.211.115.171 | Not listed | AS14061 DIGITALOCEAN-ASN | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-10-20 15:48:07 | https://kronosbrasil.com.br/wp-content/75863870... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-10-20 17:38:53 | b5933f1e9cda9927074ef0e3a34160c567aa03c76cdd96571e25349448e1a7c4 | doc | Heodo | |
| 2020-10-20 17:15:31 | dc4424c660cc882687e934977d90d1e7725602d1d702466653d1968d2ac1a066 | doc | Heodo | |
| 2020-10-20 16:50:47 | 4deb00a4faf8cd846d7255a2cd780aa8722c1a13e7a38efefeb981758a881d2d | doc | Heodo | |
| 2020-10-20 16:33:42 | 5b1dc64f14bdc5acd69143527ffdb3809ac03de2773652c13278a55a84693079 | doc | Heodo | |
| 2020-10-20 15:48:06 | ad758bc59fac01bf0e88ea434324c0bbc246df3cbd4feb1a6f6080d05dc10d35 | doc | Heodo |
US