URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-05-02 16:32:12 | 185.90.240.218 | mail.sunucuyeri.com | Not listed | AS200977 assunucuyeri | TR | no |
| 2022-12-13 21:42:22 | 185.90.240.227 | mail.sunucuyeri.com | Not listed | AS200977 assunucuyeri | TR | no |
| 2023-04-24 02:15:54 | 31.186.11.254 | reverse-31-186-11-254.turkticaret.net | Not listed | AS197720 TURKTICARET-AS1 | TR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-02-27 23:11:18 | https://ozelmimarsinanmtal.com/UDI.php | Offline | BB17 img pw764 Qakbot | |
| 2023-02-16 18:05:48 | https://ozelmimarsinanmtal.com/image/013.gif | Offline | 1953131356 IcedID | |
| 2022-12-14 16:10:32 | https://ozelmimarsinanmtal.com/iu/index.php | Offline | BB10 iso nt005 Qakbot | |
| 2022-12-13 21:42:22 | https://ozelmimarsinanmtal.com/urs/index.php?qb... | Offline | 675 BB10 iso nt005 Qakbot |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-02-27 23:36:51 | 0248fa77a59f3009584ff5e557f3124c7b78b6a2165701b52a9bb96ee60783e7 | zip | ||
| 2023-02-27 23:11:18 | f4366553a4408ef70156cc9d550e11e7be7ca07fd7f95915e16632ae14d45e8e | zip | ||
| 2023-02-16 18:05:48 | 168e8a92e64f024346dd703ed9356f4e0bdf7d2130048e68da36291bbc9421a1 | dll | IcedID | |
| 2022-12-15 00:50:50 | 12aa163a59c27250800640dca463677e047df6ec7c45e41844809d716a0abfb8 | zip | ||
| 2022-12-14 16:10:32 | cd52504f8154c6d799eb0028d6f18739ca55b8a32b67d0d6163f112b3a70e57d | zip | ||
| 2022-12-14 08:54:32 | 3082df8d475a27b02d192d6e357f59282745b6075583f476710e0e150694fa1a | zip |
TR