URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-10-13 16:58:04 | 188.114.96.3 | SBL690066 | AS13335 CLOUDFLARENET | n/a | yes | |
| 2023-10-13 16:58:04 | 188.114.97.3 | SBL691350 | AS13335 CLOUDFLARENET | n/a | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-10-25 11:41:14 | https://niveen.net/ovit/ | Offline | Pikabot TA577 TR zip | |
| 2023-10-13 16:58:04 | https://niveen.net/ib/?p=3016451 | Offline | DarkGate |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-10-26 00:05:20 | aca3a402af06afb12a31952f591596317d18565a4abfaae261a3affe5d7fdf78 | zip | ||
| 2023-10-25 11:56:20 | 709640c28a1d8aa7a61aab735263b378fa9742f2cc42cbb51417e3280f6aa1b5 | zip | ||
| 2023-10-25 11:41:14 | c036d4c40d34a47beb562dce996ee461de271597277902863b14949f89933c39 | zip | ||
| 2023-10-14 17:07:31 | 940f6cfa445f6dc86ceb3e8a4ff519e53482dd58aa1d6b746241b57cf4eac7cb | zip | ||
| 2023-10-14 05:05:15 | 4c8f99015d91b885366329f6508ac9290aae0c7120be294bcccd9badf2400126 | zip | ||
| 2023-10-13 17:04:10 | 7095acfd63c35634aa336f6c1d48561fe67d5101676f9db0bb3fd13f6dc08ede | zip |
