URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-16 06:51:08 | 199.36.158.100 | SBL687840 | AS54113 FASTLY | US | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-09-16 06:51:08 | https://pcare.ai/AI_Fixer.exe | Offline | exe pcoptimizer rustystealer stealer | |
| 2025-09-16 06:51:08 | https://pcare.ai/AI_Scanner.exe | Offline | exe pcoptimizer rustystealer signed-malware stealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-09-16 10:16:23 | dee88264b79a749b318281aa2f9ac1c4659b6cab665deb0d33af4e5f29010e1a | exe | RustyStealer | |
| 2025-09-16 06:51:08 | 3263a4054b5b36cd0fed38f3a54df1d595095c73de2ec14dc9541374635f78cc | exe | RustyStealer | |
| 2025-09-16 06:51:08 | e05468a512d77fe2369ff78cdf2654f307a2a9a29581ec0c0b0eedca4e694aa6 | exe |
