URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 10:53:17 | 13.248.243.5 | a16e665f42988324c.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-04-28 10:53:17 | 76.223.105.230 | a16e665f42988324c.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2021-08-07 07:28:07 | 45.125.109.74 | Not listed | AS26658 HENGTONG-IDC-LLC | HK | no | |
| 2021-07-03 12:40:14 | 143.92.56.157 | SBL664725 | AS152194 CTGSERVERLIMITED-AS-AP | SG | no | |
| 2021-04-02 00:32:43 | 91.195.240.94 | Not listed | AS47846 SEDO-AS | DE | no | |
| 2021-01-26 16:50:13 | 67.215.229.60 | Not listed | AS36352 AS-COLOCROSSING | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-01-26 16:50:13 | http://olooom.com/sma9d6.zip | Offline | Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-03-10 23:26:27 | 91559f2eb4144acba43b4dcb51416e78b70e903c9357ce6a74afa49d0f07e184 | dll | Dridex | |
| 2021-01-26 16:50:11 | b6cf019dca618ebc676b84c40846e0a9a2050689b35845af2f12a93442fb25e8 | dll | Dridex |
US
HK
SG
DE