URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: microsoft-auth-network.cc
Domain registrar:Epik -
Domain registration date:2022-08-30 11:27:03 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-02-26 06:36:09 UTC
Total malware sites :35
Online malware sites :0 (0%)
Offline Malware sites :35 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 22:39:45 209.196.146.115Not listedAS394456 EPIK-LLC- USno
2025-03-12 23:04:17 87.121.84.254SBL683025AS215925 VPSVAULTHOST- USno
2025-01-04 14:40:40 91.202.233.151SBL677411AS200593 PROSPERO-AS- TMno
2025-01-04 01:21:43 91.212.166.134SBL624670AS198953 proton66- RUno
2024-12-22 01:48:42 5.252.155.2Not listedAS215826 Partner-Hosting-LTD- PAno
2024-12-11 22:47:26 85.31.47.154Not listedAS397423 TIER-NET- BGno
2024-11-27 01:34:51 87.121.86.16Not listedAS209693 OC-NETWORK- EEno
2023-06-27 11:08:36 85.217.144.194Not listedAS16276 OVH- GBno
2023-03-13 06:00:51 85.217.144.162Not listedAS16276 OVH- GBno
2023-02-26 06:36:11 84.32.190.45Not listedAS59642 CHERRYSERVERS2-AS- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-18 12:03:05http://microsoft-auth-network.cc/1337/TORRENTOL...Offlineexe LummaStealer opendir NDA0E
2025-03-18 12:03:05http://microsoft-auth-network.cc/TPBActivetor/T...Offlineexe LummaStealer opendir NDA0E
2024-11-01 15:19:09http://microsoft-auth-network.cc/update/TPB-1.exeOfflineLummaStealer Vidar ext abus3reports
2024-07-13 12:36:11http://microsoft-auth-network.cc/1337/B.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:38http://microsoft-auth-network.cc/1337/D.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:16http://microsoft-auth-network.cc/1337/A.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:11http://microsoft-auth-network.cc/TPBActivetor/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:11http://microsoft-auth-network.cc/FreeApps/link3...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:08http://microsoft-auth-network.cc/HEXO-SOFTWARE/...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:07http://microsoft-auth-network.cc/TPBActivetor/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:35:07http://microsoft-auth-network.cc/TPBActivetor/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:56http://microsoft-auth-network.cc/limetor/link2.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:52http://microsoft-auth-network.cc/1337/C.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:51http://microsoft-auth-network.cc/limetor/link4.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:46http://microsoft-auth-network.cc/FreeApps/link.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:45http://microsoft-auth-network.cc/TPBActivetor/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:39http://microsoft-auth-network.cc/TORRENT-SPAM/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:35http://microsoft-auth-network.cc/limetor/link3.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:33http://microsoft-auth-network.cc/FreeApps/link4...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:32http://microsoft-auth-network.cc/HEXO-SOFTWARE/...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:31http://microsoft-auth-network.cc/1337/E.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:30http://microsoft-auth-network.cc/FreeApps/link2...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:26http://microsoft-auth-network.cc/limetor/link.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:34:14http://microsoft-auth-network.cc/TORRENT-SPAM/l...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:17:20http://microsoft-auth-network.cc/newz2k/link3.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:17:18http://microsoft-auth-network.cc/newz2k/link4.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:17:15http://microsoft-auth-network.cc/newz2k/link2.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 12:17:10http://microsoft-auth-network.cc/newz2k/link.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 11:48:34http://microsoft-auth-network.cc/TG-Source/link...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 11:48:21http://microsoft-auth-network.cc/TG-Source/link...Offline185.99.135.162 ascii link opendir NDA0E
2024-07-13 11:46:37http://microsoft-auth-network.cc/TPB-G/link.txtOffline185.99.135.162 ascii link opendir NDA0E
2024-07-13 11:45:17http://microsoft-auth-network.cc/update/link.txtOffline185.99.135.162 ascii link opendir NDA0E
2023-02-26 06:36:13http://microsoft-auth-network.cc/TPB-2-Links/li...Offline185.99.135.162 ascii link opendir abuse_ch
2023-02-26 06:36:11http://microsoft-auth-network.cc/TPB-2-Links/li...Offline185.99.135.162 ascii link opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-18 17:44:0866b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-18 17:15:0766b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-18 16:40:1766b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-10 21:42:53ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-06-10 21:38:01ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-06-10 21:35:47ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-05-18 22:04:31796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-05-18 21:29:12796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-05-18 21:13:09796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-04-18 00:26:33cbef641ab5e6e4e29ee57ff1d05d64848f21f7aeab1fb25043b953a85b95a4a1exe 
2025-04-12 14:23:494ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-04-12 13:44:134ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-04-12 13:42:564ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-03-23 22:40:108c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-23 22:23:098c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-23 21:18:098c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-18 12:03:05b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-03-18 12:03:05b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-03-16 02:19:507222e418982845a613b0ff6c842bf8d194dd5109a6436b32953f67d7bba35585exe  
2025-03-03 11:02:20b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-03-03 10:45:43b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-02-17 18:08:5612b096048be2cca3f61e8fe031efa942faf8f4c31cbafe76953b744537275aceexe LummaStealer
2025-02-17 17:09:1712b096048be2cca3f61e8fe031efa942faf8f4c31cbafe76953b744537275aceexe LummaStealer
2025-02-03 13:11:118bc4c1e92cfffe6d52dd7f5c65263e24dbc7bc470dbf631e782afd5e90ef5ee3exe LummaStealer
2025-02-03 11:18:118bc4c1e92cfffe6d52dd7f5c65263e24dbc7bc470dbf631e782afd5e90ef5ee3exe LummaStealer
2025-01-29 16:46:56d4fb0e3c1d8a97e3b3baedabd704ef849e7fc96ac1c1b08801585ba4ee11fd29exe LummaStealer
2025-01-29 14:05:15d4fb0e3c1d8a97e3b3baedabd704ef849e7fc96ac1c1b08801585ba4ee11fd29exe LummaStealer
2025-01-29 08:43:0205d19250d7f78428660571d9f14755b27c1c94b68a7da1916a0909a9ca6c3beeexe  
2025-01-29 08:41:3805d19250d7f78428660571d9f14755b27c1c94b68a7da1916a0909a9ca6c3beeexe  
2025-01-18 23:08:527902e87ab677a55e32d8d354a1b225c67c89c871cdd711771dc5399f57fd6aefexeLummaStealer
2025-01-18 23:06:567902e87ab677a55e32d8d354a1b225c67c89c871cdd711771dc5399f57fd6aefexeLummaStealer
2025-01-04 04:18:519c4afe3e68312e44bbaa3f122a251bb087f72d94adf8d432bdd8382087086c92exeLummaStealer
2025-01-04 01:21:429c4afe3e68312e44bbaa3f122a251bb087f72d94adf8d432bdd8382087086c92exeLummaStealer
2024-12-22 07:19:59f2c2df5d625c6983881695ab53416c52aa574821e01074f607b6039e5d79e76fexe Vidar
2024-12-22 01:48:40f2c2df5d625c6983881695ab53416c52aa574821e01074f607b6039e5d79e76fexe Vidar
2024-12-16 11:18:185746d38d3f64fd37ad4aa158d119eec1378e6298bd105323d5ffc791b9f5e88aexeVidar
2024-12-15 16:19:595746d38d3f64fd37ad4aa158d119eec1378e6298bd105323d5ffc791b9f5e88aexeVidar
2024-12-05 10:01:52a3a6cde465591377afc5f656f72a00799398fd2541b60391bcb8f62b8f8cace3exe Vidar
2024-11-27 01:34:50b33f25c28bf15a787d41472717270301071af4f10ec93fa064c96e1a33455c35exe Vidar
2024-11-19 00:37:3998f1e9d201c49c501fdb01a3f325d301dde90facccf219db61a35bf99fa38952exe Vidar
2024-11-11 09:42:38a2798b69026fb2332e89ddd9ba0ddb82b7d658231bf8e4edd2577e25b76a0395exe Vidar
2024-11-03 15:41:59912320095089137ef3327b9a9682a87966308e44217ab77234e7bf5475496419exe Vidar
2024-11-01 15:19:0918f5f368c18b9988c7d66abb169d54029cb6316910b109f3e3a4dbcc37a5b59cexeVidar