URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-30 07:56:59 | 81.169.145.160 | wa0.rzone.de | Not listed | AS6724 STRATO | DE | yes |
| 2025-04-27 13:04:56 | 85.215.105.215 | mail.dev-it.de | Not listed | AS8560 IONOS-AS | DE | no |
| 2019-10-25 08:46:35 | 95.142.66.25 | srv.dev-it.de | Not listed | AS51483 SASG | DE | no |
| 2019-05-23 17:45:12 | 95.142.66.221 | deb1vm.dev-its.de | Not listed | AS51483 SASG | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-05-23 17:45:12 | http://motorradecke-richter.de/wp-content/theme... | Offline | exe Troldesh |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2019-07-04 01:42:06 | bb6f355ea11ee4a879d7c7ee97c44e06cae6021d9cb23c1df28491336662afff | exe | Ransomware.Troldesh | |
| 2019-07-03 14:23:00 | 501ef03f71805e07dca0acddb4c168cb588b5bc070aa1d692427a037a47d1535 | exe | Ransomware.Troldesh | |
| 2019-07-03 05:18:03 | bf54c931aa1b614c3f439e6c637cfd5c1c65cf71fc217cc2540ef349b61e0ec5 | exe | Ransomware.Troldesh | |
| 2019-05-23 17:45:11 | e5093e304a50d34cdf67ee8e49713c6131d6740e664ea49d9c98682336e3141a | exe | Ransomware.Troldesh |
DE