URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-07-18 15:50:31 | 47.76.127.217 | Not listed | AS45102 ALIBABA-CN-NET | HK | no | |
| 2025-07-18 15:50:31 | 47.91.170.222 | Not listed | AS45102 ALIBABA-CN-NET | HK | no | |
| 2025-07-18 15:50:31 | 8.218.208.240 | Not listed | AS45102 ALIBABA-CN-NET | HK | no | |
| 2019-04-18 07:37:33 | 66.198.240.17 | ssr17.supercp.com | Not listed | AS55293 A2HOSTING | US | no |
| 2019-03-19 22:03:05 | 209.205.207.130 | standard4.doveserver.com | Not listed | AS55081 24SHELLS | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-03-19 22:13:08 | http://thesagehillsschool.com/wp-content/themes... | Offline | exe Troldesh | |
| 2019-03-19 22:09:37 | http://thesagehillsschool.com/wp-content/themes... | Offline | exe Troldesh | |
| 2019-03-19 22:09:22 | http://thesagehillsschool.com/wp-content/themes... | Offline | exe | |
| 2019-03-19 22:03:05 | http://thesagehillsschool.com/wp-content/themes... | Offline | exe Troldesh |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2019-04-24 17:47:56 | 8329747c26163c83f0b0610be5c997795b71aec81d4b1f4928a194a4fb43c489 | exe | ||
| 2019-04-23 09:40:54 | 83d55c87926b28692829455067a55487c884324dcec49883e0f5e9940519011e | exe | ||
| 2019-04-23 03:50:18 | 119fe82934ec4e21f1907238474ad7a7ca9cdaec941c9bc0842e4af9fad00f57 | exe | ||
| 2019-04-21 18:45:11 | 9aed7831b3c972c54115a837c379219f29b43a218fde07b5bcee4de24aa68019 | exe | ||
| 2019-03-19 22:13:08 | d5fe31471af8abcd884108fbbfe776c3df6c988a865e401fc83ccbdfe030ed4e | exe | Ransomware.Troldesh | |
| 2019-03-19 22:09:37 | 50119da56e84ae4baa207a9391a0143fe5aa66c212aeba08e2d6d864af0a0d83 | exe | Ransomware.Troldesh | |
| 2019-03-19 22:09:22 | 86fc216137adc0099a89c0c41d0cf713ee7ea62973cbc54060167db6b606373e | exe | ||
| 2019-03-19 22:03:05 | fec5824e87550fc4981606030d7b74f6d00b001de536916b95f7c1d24a8113d8 | exe | Ransomware.Troldesh |
HK
US