URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2021-10-28 09:37:22 | 185.108.182.231 | host-185-108-182-231.itsec.md | Not listed | AS39279 CTS-MD | MD | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-11-01 13:46:10 | http://map.cnam.md/wp-admin/maxfile.exe | Offline | Formbook | |
| 2021-10-28 10:07:04 | http://map.cnam.md/wp-admin/Mfile.exe | Offline | exe Formbook | |
| 2021-10-28 10:05:06 | http://map.cnam.md/wp-admin/maxi.exe | Offline | Formbook | |
| 2021-10-28 10:05:04 | http://map.cnam.md/wp-admin/kon.exe | Offline | AgentTesla | |
| 2021-10-28 09:37:22 | http://map.cnam.md/wp-admin/kontrol.exe | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-11-01 13:46:09 | 4cd1e6edc08c369a7e62542c25d5918fdfdc7d7729a078be8235604e20a60302 | exe | Formbook | |
| 2021-11-01 08:45:43 | f35fc25744c072c013f79cac8eeb7c67cf7abd3261a57dbfbe3aed9b300171a0 | exe | AgentTesla | |
| 2021-10-28 10:07:04 | 9a6e0dd1aa4fe9b84fd6addd707202aacf0e296c30ab3e49fa2e1aed6dba4ad3 | exe | Formbook | |
| 2021-10-28 10:05:06 | 8a13ce3da212f3557c8d3f43a375fa6e030b400c2da2ca9701bed88f839863fc | exe | Formbook | |
| 2021-10-28 10:05:04 | 963d9644b56b92d640fb303f43ca8ef5a4fd72e2859c144fb1f911424f9bf755 | exe | AgentTesla | |
| 2021-10-28 09:37:22 | 5b712afada02227636f5a384fd514cd8527302b03a98132aeb12ec92c4eb63f1 | exe | AgentTesla |
MD