URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2019-09-08 10:49:52 | 37.52.9.2 | 2-9-52-37.pool.ukrtel.net | Not listed | AS6849 UKRTELNET | UA | no |
| 2019-05-29 20:59:46 | 94.53.120.109 | 94-53-120-109.next-gen.ro | Not listed | AS48161 NG-AS | RO | no |
| 2019-08-31 16:34:26 | 195.70.44.19 | Not listed | AS5483 MAGYAR-TELEKOM-MAIN-AS | HU | no | |
| 2019-05-06 18:39:13 | 91.190.184.184 | example.com | Not listed | AS7029 WINDSTREAM | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-05-06 18:39:13 | http://upsabi.ninth.biz/upsabi.exe | Offline | CoinMiner exe |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2019-08-14 14:25:29 | c4e7c5f654b5d5821b24df9ab3a9194a127f31daa8ba504cf9de345a5e096e5b | exe | ||
| 2019-05-06 18:39:12 | e97c8416fc63162b69167c2b4f51f82ae6aacc8e4276b76ca5b775ba2ec437ea | exe | CoinMiner |
UA
RO
HU
US