URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-09-28 18:07:42 | 198.12.126.210 | wgh1.wghservers.com | Not listed | AS36352 AS-COLOCROSSING | US | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-09-28 18:07:42 | https://natwalliance.com/ixme/moutsaltpouituv | Offline | bb H322 H436 Qakbot |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-10-08 17:42:40 | 8cdb61a3816a7863d2e0f15b69bd9441d0cf95866b72b92a67afa32e9ac396a0 | zip | Quakbot | |
| 2022-10-04 10:15:15 | fe8eafd15eb657e9330a1781b07b2539f74849f614a0e60aeb8e030c9c141912 | zip | ||
| 2022-10-01 13:05:53 | ce02af62274b3a226acbf52f15adc5144c5eb2ae009174c84168e9bb3f048898 | zip | ||
| 2022-09-30 10:02:15 | b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9be | zip | Quakbot | |
| 2022-09-29 15:32:02 | 466b66315bf1fa84c9538469caada0735f9fceab44ab1b47aea1250f0b77fd95 | zip | ||
| 2022-09-29 06:50:54 | 0ad6192b4105c85c439fbc015b2e26d9ef3902995d4d90bbf0e4212a9d6abd94 | zip | ||
| 2022-09-28 23:13:30 | e05947f4870002d493a27af3145204bae9eb68a23c1d54ffd56b705791737301 | zip |
US