URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-21 07:55:42 | 18.119.181.229 | ec2-18-119-181-229.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-21 07:55:41 | 3.132.235.18 | ec2-3-132-235-18.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-14 11:17:24 | 3.140.230.102 | ec2-3-140-230-102.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-21 07:55:42 | 3.142.104.129 | ec2-3-142-104-129.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-26 15:33:55 | 3.148.83.101 | ec2-3-148-83-101.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-21 07:55:41 | 3.149.186.150 | ec2-3-149-186-150.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-11-16 15:23:39 | 3.148.130.100 | ec2-3-148-130-100.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-11-16 15:23:39 | 3.151.116.45 | ec2-3-151-116-45.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-11-17 20:23:18 | 3.151.232.151 | ec2-3-151-232-151.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-11-19 18:03:44 | 13.58.237.179 | ec2-13-58-237-179.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-09-24 07:20:33 | https://tipjar.id/q44agl0h.jpg | Offline | Dridex | Anonymous |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-09-24 07:20:32 | 3ab48ca45cd8a40aa0100279752afd3e89003bb85bf420c8b1be62e019f4c9eb | dll | Dridex |
US