URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2020-12-08 07:10:04 | 213.181.192.180 | host-213-181-192-180.wave-net.hu | Not listed | AS47159 CELLKABEL | HU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-12-14 08:37:03 | http://runningcrewteam.com/goga/deck/DEKK.scr | Offline | scr | |
| 2020-12-08 08:46:04 | http://runningcrewteam.com/Docx/zi/uNuFJEE0x7Ro... | Offline | AgentTesla | |
| 2020-12-08 07:10:05 | http://runningcrewteam.com/Docx/ok/McgjQSIvvkl7... | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-12-14 08:37:03 | 83fe806f938f4231952afb7890f89689234b4b40dfd6f5f0b1ffdbeb7519dd06 | exe | ||
| 2020-12-08 08:46:04 | 0e7faca21872dcc89d08e434bc653e24642dc8a6533db6255a2678fbcdba3f8b | exe | AgentTesla | |
| 2020-12-08 07:10:04 | 3be787bec6c661048c534c126761c2be937e70cb5ce8f1922cca5f4f22106b54 | exe | AgentTesla |
HU