URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-01-30 15:12:08 | 122.241.172.192 | Not listed | AS4134 CHINANET-BACKBONE | CN | no | |
| 2021-11-24 20:07:07 | 222.211.72.29 | 29.72.211.222.broad.my.sc.dynamic.163data.com.cn | Not listed | AS4134 CHINANET-BACKBONE | CN | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-11-26 05:11:10 | http://mastertest.f3322.net:35641/downler.exe | Offline | 32 exe Gh0stRAT | |
| 2021-11-24 20:07:07 | http://mastertest.f3322.net:35641/bjd.exe | Offline | exe Gh0stRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-01-04 04:21:49 | 8d69aa842c3f6828f6ba7c200ed6e67a04329a301843ae6653afa2869ccda6b0 | exe | Gh0stRAT | |
| 2021-12-02 09:00:31 | 42b18b49fbe82352ff2d63e98e44c872d2273b9cca6e11ccf24949881fd88449 | exe | ||
| 2021-12-02 06:45:18 | 316b27d6ad1ad3ea6480f7b381bd41d48df9e3535cf2529f46bef48cae875eb5 | exe | ||
| 2021-12-01 17:10:51 | 3932aa428e2b3ba829733ff447943f37dd4bc00e60a1e217432e9f960b0f5b11 | exe | ||
| 2021-12-01 17:02:10 | 6c26497ca98f9e78fa14eff1e15654ccf2ab31fd55894e0e04102563f252afa3 | exe | ||
| 2021-11-26 05:11:10 | 85b28249fe4da7de9cb2ec4bd4b6d9729684b35cb6326462dac08a43accee58e | exe | Gh0stRAT | |
| 2021-11-24 20:07:07 | 4b4c466ee72c0d623339564402175b47d68189d129bc9c3e61d0a8a504265acc | exe | Gh0stRAT |

CN