URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-10-02 17:08:12 | 172.67.138.246 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-10-02 17:08:13 | 104.21.48.247 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-09-18 04:36:38 | 91.226.30.3 | Not listed | AS8342 RTCOMM-AS | RU | no | |
| 2023-08-15 01:38:36 | 194.67.71.33 | Not listed | AS197695 AS-REGRU | RU | no | |
| 2025-08-21 13:10:06 | 194.67.71.128 | Not listed | AS197695 AS-REGRU | RU | no | |
| 2025-04-27 14:27:31 | 193.203.190.8 | srv795111.hstgr.cloud | Not listed | AS47583 AS-HOSTINGER | FR | no |
| 2023-08-27 15:14:24 | 83.222.10.218 | Not listed | AS9123 TimeWeb-AS | RU | no | |
| 2023-08-09 16:44:06 | 188.225.84.42 | vds-shopvds.timeweb.ru | Not listed | AS9123 TimeWeb-AS | RU | no |
| 2025-09-11 16:59:09 | 194.67.71.115 | Not listed | AS197695 AS-REGRU | RU | no | |
| 2025-08-25 04:30:57 | 194.67.71.119 | Not listed | AS197695 AS-REGRU | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-08-09 16:44:06 | https://pilkishop.ru/images.exe | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-08-09 16:44:05 | b20ff3d16c6b4dd805900ca612d4ad54ad1d9cfe8163805353538764ba38c9ce | exe | AgentTesla |

FR