URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-08-04 13:50:45 | 149.50.140.200 | vps-4103785-x.dattaweb.com | Not listed | AS27823 Dattatec.com | AR | yes |
| 2023-01-09 20:51:59 | 162.240.209.119 | vps-789868.tikibar.space | Not listed | AS46606 UNIFIEDLAYER-AS-1 | US | no |
| 2022-09-10 05:17:10 | 162.214.196.147 | vps-376870.mikrobalancing.com | Not listed | AS46606 UNIFIEDLAYER-AS-1 | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-09-10 05:17:10 | https://proyectoweb.net/assets/vendor/animate/n... | Offline | dropby PrivateLoader RedLineStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-09-11 14:39:10 | dabc32cc27fee344390ce8de6e7dc23befe2819b1ed19c06166c9df1f3e6b056 | exe | RedLineStealer | |
| 2022-09-10 14:06:55 | 48b7969c0e98ceeaf092239414881993f0a55152956fd59e1da14e2da01ee4fd | exe | RedLineStealer | |
| 2022-09-10 11:20:17 | d671ad5ae7f3211b7582407339bf7bac0a6c861e400749f8a612d86088746ea7 | exe | RedLineStealer | |
| 2022-09-10 05:17:09 | 57edb17976437e8a4d8ccfa21d83fdfcc3ccfb6077482bf2138b4553f6922afc | exe | RedLineStealer |

AR