URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-24 10:34:45 | 103.30.147.90 | ganjuran.idweb.host | Not listed | AS46050 JOGJACAMP-AS-ID | ID | yes |
| 2025-07-02 20:05:08 | 203.161.184.43 | ganjuran.idweb.host | Not listed | AS46050 JOGJACAMP-AS-ID | ID | no |
| 2025-05-03 03:17:56 | 203.161.184.51 | semanu.idweb.host | Not listed | AS46050 JOGJACAMP-AS-ID | ID | no |
| 2021-11-14 20:42:13 | 203.161.184.100 | rejowinangun.idweb.host | Not listed | AS46050 JOGJACAMP-AS-ID | ID | no |
| 2021-10-06 08:40:15 | 202.52.146.120 | ipv4-202-52-146-120.idweb.host | Not listed | AS45324 GMEDIA-AS-ID | ID | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-10-06 08:40:15 | https://spia-indonesia.org/cqi-bin/RM0nXQmWlMxk... | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-10-06 08:40:14 | 01379012d67f89754a8918382ac8b24a796704a5831fc6a7bf21f7d5afa31c20 | exe | AgentTesla |
