URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 07:01:18 | 208.91.197.27 | Not listed | AS40034 CONFLUENCE-NETWORK-INC | VG | yes | |
| 2020-12-22 20:53:04 | 104.131.245.35 | Not listed | AS14061 DIGITALOCEAN-ASN | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-12-22 20:53:04 | http://mtbj.net/gstreamer-h264-vsy9z/2lwLo/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-12-22 21:42:29 | 6420b73153baa8bc93494e5f2cac6f1248c102e7bfccb497d71bc67791603ca3 | doc | Heodo | |
| 2020-12-22 21:23:31 | bf43a06432e503ed88a05c1152818a93af5c9f028441b60e6154dabfab072faf | doc | Heodo | |
| 2020-12-22 21:07:09 | ac4a11a17747f0db974bbb343bdf32d636c82bc667c3223c23567faab4377ecc | doc | Heodo | |
| 2020-12-22 20:53:04 | 0e0a8e32415a80ba95b8af747d13f3b6312498145d1677df7641ba3c9cf8e9b6 | doc | Heodo |
VG
US