URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-11-24 04:00:13 | 103.221.221.70 | Not listed | AS63760 AZDIGI-AS-VN | VN | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-11-24 17:07:11 | https://tungphamblog.com/fortune.exe | Offline | dropped-by-PrivateLoader LummaStealer | |
| 2023-11-24 04:00:13 | https://tungphamblog.com/Kolodi.exe | Offline | 32 exe RedLineStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-01-09 07:49:12 | 18beee57e6cc29f57b160975a306e6cfcb240cecc031a07f1f7e1801374489c3 | exe | ||
| 2023-11-28 19:00:13 | 2237206ab4781be0819359540bb08409783ebf853e5df60e4683ff60ea3e7f5c | exe | RedLineStealer | |
| 2023-11-27 16:56:39 | a719b6410b2e125322b304e54d98ff5273d5e097aafce82f8acadca572d1c522 | exe | RedLineStealer | |
| 2023-11-25 16:11:52 | c189f0fb469d1614cabaf2c7ecad116504f2a89da8c51f371dd28571dc45a13c | exe | RedLineStealer | |
| 2023-11-24 18:37:00 | 6afc7d0eea79bfc7721b0299c38c99740b57766a1dee973f8ff7219f3cca9dd7 | exe | RedLineStealer | |
| 2023-11-24 17:07:11 | 9aed8f04dac114dc7912bc3d8a931715629c083b2d75b4361d554384f4d32177 | exe | LummaStealer | |
| 2023-11-24 04:00:13 | f7a1d39832ffeb8e521d78612d2e509e7bc14d96a98b1db48191f7c23b893caf | exe | RedLineStealer |

VN