URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-02 00:32:47 | 94.156.65.252 | taeniada252.nonsexual94.builder-marketing.com | Not listed | AS208893 sparks | GB | yes |
| 2023-08-30 08:23:40 | 193.42.32.61 | Not listed | AS214396 SUDOLIO-AS | SK | no | |
| 2023-06-10 10:11:09 | 85.209.134.253 | Not listed | AS41745 FORTIS-AS | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-06-10 10:11:09 | http://race.ydns.eu/rate/saw.com | Offline | PureCrypter |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-06-14 04:56:01 | 01b22c6616dab755850192f2580e982635a28dbb98b868e36cbb483a15da90a4 | exe | ||
| 2023-06-13 15:02:43 | 434059c2dd4abfb50b823671edb43696e4363e55692f913c1da856f9a1ecf6c3 | exe | ||
| 2023-06-12 05:51:57 | 085758594b8004ffcd2c0b7413d67c3fd8024d8915aac54b95db59609c7bd55d | exe | PureCrypter | |
| 2023-06-11 06:55:04 | 7aae9c3c1ffb5983de4c595a757f5f3d970ee895a17948aa17394cabd2910d78 | exe | PureCrypter | |
| 2023-06-10 10:11:09 | 22cdb432f7d20f06b120789c7f089f7b376d02a7d1576b3ab0e31456376ef47b | exe |
GB
SK
US