URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 13:06:44 | 167.235.84.109 | cloud09.nordic.hosting | Not listed | AS24940 HETZNER-AS | DE | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-07-28 07:14:19 | http://skare.net/cgi-bin/uKq/ | Offline | emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-07-31 23:38:15 | b03ff55cd67297d4bfee7d88220f770c67db4fcab2076587e2afd398353c5365 | exe | Heodo | |
| 2020-07-28 08:07:54 | 83267d1c1b63552a5fbd022b2b15e37c78b6cb27eb58049ddd15318c223661e6 | exe | Heodo | |
| 2020-07-28 07:52:07 | 9fef990cf00d13fc01786ce669b61f8fe9ef11fc509fd6b551ed22953dc0ec0e | exe | Heodo | |
| 2020-07-28 07:36:14 | bf6ea9f9e809e9e218e15ba673bc2eccecedf761e0c195fc64e4b99e748eaba3 | exe | Heodo | |
| 2020-07-28 07:14:19 | 3a6c2bd2d065d2da7ad6a2361ee59e129cc461f53360534cc234ab7214200924 | exe | Heodo |
DE