URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-11-16 05:02:45 | 13.225.223.30 | server-13-225-223-30.jfk51.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-11-16 05:02:45 | 13.225.223.39 | server-13-225-223-39.jfk51.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-11-16 05:02:45 | 13.225.223.94 | server-13-225-223-94.jfk51.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-11-16 05:02:45 | 13.225.223.95 | server-13-225-223-95.jfk51.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-07 21:19:30 | 143.204.191.117 | server-143-204-191-117.lhr3.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-07 21:19:30 | 143.204.191.13 | server-143-204-191-13.lhr3.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-07 21:19:29 | 143.204.191.64 | server-143-204-191-64.lhr3.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-07 21:19:29 | 143.204.191.96 | server-143-204-191-96.lhr3.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-17 13:34:06 | 18.165.201.108 | server-18-165-201-108.lhr50.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-05-17 13:34:06 | 18.165.201.39 | server-18-165-201-39.lhr50.r.cloudfront.net | Not listed | AS16509 AMAZON-02 | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-08-13 13:12:06 | http://ladygagaagogo.com/g5/RFQ.exe | Offline | 32 exe GuLoader |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-08-13 13:12:05 | afc7d530c112b47cd33295262f533df60f12568ede477091434381b0d6a2cc8c | exe | GuLoader |
US