URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-17 18:06:00 | 188.114.96.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-09-17 18:06:00 | 188.114.97.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-04-27 13:00:06 | 104.21.112.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.16.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.32.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.48.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.64.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.80.1 | SBL681411 | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-27 13:00:06 | 104.21.96.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2022-02-03 15:15:42 | 45.84.206.54 | cpl35.main-hosting.eu | Not listed | AS47583 AS-HOSTINGER | LT | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-01-24 18:26:12 | http://margos.org/dda/SYNT.exe | Offline | exe GuLoader | |
| 2022-01-17 07:57:10 | http://margos.org/k6/putty.exe | Offline | AveMariaRAT | |
| 2022-01-17 07:57:07 | http://margos.org/k7/putty.exe | Offline | AveMariaRAT | |
| 2021-08-13 13:27:07 | http://margos.org/a1/ORI.exe | Offline | 32 AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-01-24 18:26:12 | 4486318d812a32852db5a4b8bd19dc456890b6c9a1bd03ffe94e2ef189394d90 | exe | GuLoader | |
| 2022-01-17 07:57:09 | dcdc2b5d1d114dbd7072c7c66751359e1e1fa28ce4679e2e8124f86a65a2d600 | exe | AveMariaRAT | |
| 2022-01-17 07:57:07 | dcdc2b5d1d114dbd7072c7c66751359e1e1fa28ce4679e2e8124f86a65a2d600 | exe | AveMariaRAT | |
| 2021-08-13 13:27:06 | 09648c6629005ee5dc288fd1648a19fcca30422a817e8766d51d73becd619ce4 | exe | AgentTesla |

LT