URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-25 21:11:28 | 76.76.21.21 | Not listed | AS16509 AMAZON-02 | US | yes | |
| 2025-04-27 07:52:04 | 209.38.208.141 | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no | |
| 2021-11-16 03:55:28 | 88.218.2.24 | client-88-218-2-24.pronetit.ro | Not listed | AS9009 M247 | PL | no |
| 2021-09-08 02:25:55 | 88.218.2.22 | sv.inside-hosting.com.2.218.88.in-addr.arpa | Not listed | AS9009 M247 | PL | no |
| 2021-08-22 13:40:54 | 88.218.2.20 | client-88-218-2-20.pronetit.ro | Not listed | AS9009 M247 | PL | no |
| 2021-07-21 06:47:11 | 86.121.3.16 | 86-121-3-16.rdsnet.ro | Not listed | AS8708 DIGI-ROMANIA | RO | no |
| 2021-06-26 07:23:04 | 5.2.142.39 | static-5-2-142-39.rdsnet.ro | Not listed | AS8708 DIGI-ROMANIA | RO | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-06-26 07:23:04 | https://manomir.ro/egoigwe.exe | Offline | exe SnakeKeylogger | |
| 2021-06-26 07:23:04 | https://manomir.ro/onyeala.exe | Offline | AZORult |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-06-26 07:23:04 | 05bc6befa45c61005487004f802ed45110b5be2fc4ac24063dc98b168dfb8801 | exe | SnakeKeylogger | |
| 2021-06-26 07:23:04 | 74f108a1e08fa3ebc3ff8e54f4950e5fa1e75a6e4a9a9968e226b31064fe8d2b | exe | AZORult |
US
DE
PL
RO