URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2024-09-19 04:35:11 | 203.175.9.144 | ambun.dua.rumahweb.net | Not listed | AS58487 CRI-AS-AP | ID | yes |
| 2025-07-28 23:17:57 | 103.253.215.19 | Not listed | AS58487 CRI-AS-AP | ID | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2024-09-19 21:24:06 | https://nasionaltv.com/vejsfs16.exe | Offline | dropped-by-PrivateLoader encrypted Vidar | |
| 2024-09-19 14:58:34 | https://nasionaltv.com/ldfnsa.exe | Offline | ||
| 2024-09-19 05:08:07 | https://nasionaltv.com/vsg15.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2024-09-19 05:07:06 | https://nasionaltv.com/vdfsh12.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2024-09-19 04:35:13 | https://nasionaltv.com/vfdshf.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2024-09-19 04:35:11 | https://nasionaltv.com/shhds.exe | Offline | dropped-by-PrivateLoader MarsStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-09-19 21:24:06 | bb1d3e11f81580801efd751e641f8be49cbdbc15800aa88d3cf1c4b3b55d08af | exe | Vidar | |
| 2024-09-19 16:44:44 | d0285d1ff85d7ef17ce9e3c0b185bd93624d6fde47a2cf0ec99a8cfd4a7afb0d | exe | ||
| 2024-09-19 05:08:07 | f85d8599ca58d0d08292f94a6c51d6d8d21f050fef35862392106c549b12fba6 | exe | Vidar | |
| 2024-09-19 05:07:06 | 3493ca80cb445940439578b4535ce772ced104d2de1c2ce35f203422d325508f | exe | Vidar | |
| 2024-09-19 04:35:10 | d63d18c67f83e54c77072aa953c5e5c0496a7a4c2ac6ca8bd07e211ee80b3d6c | exe | MarsStealer | |
| 2024-09-19 04:35:10 | 6f8b44c727d44c82461e3e33098a1d93517bd200c4489120914f34e22715309c | exe | Vidar |
