URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2019-05-24 09:24:27 | 185.181.180.130 | saveh.net | Not listed | AS206596 NOOR-IDC | IR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-09-16 15:14:11 | http://saboorjaam.ir/templates/lt_corporation/c... | Offline | js Ransomware RUS Troldesh | Anonymous |
| 2019-05-24 09:24:27 | http://saboorjaam.ir/templates/lt_corporation/i... | Offline | exe Troldesh |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-07-29 07:25:50 | b06de355d7e2a425d5252c30f9626d7451ac3e2632856808a9ae4dd77a32c05e | exe | ||
| 2020-04-03 12:49:56 | 5e82223d1f4297843a57baed63869fe1a639be23c6f4848510922bee1b8fc225 | exe | ||
| 2019-11-30 14:50:50 | 5c606c7e4fb1836d29c56474bba168e8b14fde06f2a6cfed9821209561550307 | html | ||
| 2019-05-24 09:24:27 | e5093e304a50d34cdf67ee8e49713c6131d6740e664ea49d9c98682336e3141a | exe | Ransomware.Troldesh |
IR