URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-08-22 07:50:34 | 13.248.169.48 | a904c694c05102f30.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-08-22 07:50:34 | 76.223.54.146 | a904c694c05102f30.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-09-05 19:39:16 | 166.117.110.61 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2025-09-05 19:39:16 | 99.83.161.153 | a2b7bf3398455f345.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-07-16 05:26:00 | 13.248.213.45 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-07-16 05:26:00 | 76.223.67.189 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 11:36:24 | 164.90.216.186 | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no | |
| 2023-07-10 20:33:17 | 134.209.48.114 | Not listed | AS14061 DIGITALOCEAN-ASN | US | no | |
| 2023-06-26 11:13:37 | 31.129.96.74 | Not listed | AS198610 BEGET-AS | RU | no | |
| 2023-05-07 15:07:38 | 62.217.179.153 | Not listed | AS198610 BEGET-AS | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-04-15 17:51:13 | https://simdaq.com/upload/kiskis.exe | Offline | dropped-by-PrivateLoader PrivateLoader | |
| 2023-04-15 17:51:10 | https://simdaq.com/upload/vdr.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2023-04-10 06:02:19 | https://simdaq.com/file/File_pass1234.7z | Offline | 1234 7z Password-protected |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2023-04-15 17:51:13 | 31cf1d22c011317d107687c35de88ca6966ee5850978434b34ef2f74d4dec39b | exe | PrivateLoader | |
| 2023-04-15 17:51:10 | 36de150cba3d3477191cbe04958e9f887725df1e2e21a92cb18887620238dea2 | exe | Vidar | |
| 2023-04-10 10:22:03 | bdca403c0378cb709d9ec6450c78002cd6d64d04ac515afcc86cf76a528b59b9 | 7z | ||
| 2023-04-10 06:02:11 | 69fb5526fa37b31dc015bd08345bd14d19431f9fb0d96d307c4dcbee96453846 | 7z |

DE
RU