URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-12-07 23:30:31 | 191.101.79.92 | Not listed | AS47583 AS-HOSTINGER | US | yes | |
| 2021-09-27 13:29:06 | 192.185.143.195 | 192-185-143-195.unifiedlayer.com | Not listed | AS31898 ORACLE-BMC-31898 | US | no |
| 2022-06-01 00:54:34 | 45.61.48.123 | Not listed | AS36007 KAMATERA | US | no | |
| 2022-05-21 11:20:16 | 34.98.99.30 | 30.99.98.34.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | no |
| 2026-05-20 14:01:49 | 13.248.213.45 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2026-05-20 14:01:49 | 76.223.67.189 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-10-02 06:18:06 | https://maxdigitizing.com/omnis-molestiae/docum... | Offline | SQUIRRELWAFFLE TR zip | |
| 2021-10-01 16:38:08 | https://maxdigitizing.com/omnis-molestiae/dicta... | Offline | TR | Anonymous |
| 2021-09-30 10:07:04 | https://maxdigitizing.com/omnis-molestiae/iure.zip | Offline | Anonymous | |
| 2021-09-30 10:07:04 | https://maxdigitizing.com/omnis-molestiae/digni... | Offline | Anonymous | |
| 2021-09-27 13:29:06 | https://maxdigitizing.com/wAbCNMUm/pp.html | Offline | dll Qakbot |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-09-27 17:26:26 | 019148aa5fdb64670cb50970ec5e2e74da86592f522658433219b8c3314e396c | dll | Quakbot | |
| 2021-09-27 17:21:39 | 8d4756aff6d5fb729beb641bc7982a3e301f62548cfe6dc59c9fc0a5086a0462 | dll | Quakbot | |
| 2021-09-27 16:58:58 | 36180698bf4e23fd933dd4fa66e099b80ab0538bc82b6358c9cc7cae9b39abb5 | dll | Quakbot | |
| 2021-09-27 16:53:08 | 51426703eccfb0b85c4051fa36ad9830828c85434a60d7c53328bf46fd1edf5c | dll | Quakbot | |
| 2021-09-27 15:48:40 | 84aca0910107cb0b5f97bea846753fb1faf226cb179b2f8e1318b2ec3d7e21c3 | dll | Quakbot | |
| 2021-09-27 13:49:37 | 88ce871158d62a926a50c7e07aa279ba13b75e09659eb9418f612c9130389c65 | dll | Quakbot |
