URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: utorrent-server-api.cc
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Blocked
Firstseen:2023-02-26 06:36:09 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 22:53:17 209.196.146.115Not listedAS394456 EPIK-LLC- USno
2025-03-13 03:04:38 87.121.84.254SBL683025AS215925 VPSVAULTHOST- USno
2025-02-14 14:53:05 91.202.233.151SBL677411AS200593 PROSPERO-AS- TMno
2023-06-27 10:19:25 85.217.144.194Not listedAS16276 OVH- GBno
2023-03-01 17:55:14 85.217.144.162Not listedAS16276 OVH- GBno
2023-02-26 06:36:11 84.32.190.45Not listedAS59642 CHERRYSERVERS2-AS- NLno

Malware URLs


The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-18 17:17:4966b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-18 17:01:0666b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-18 12:03:4266b6fc4a116af7fc4749b6e135206895770cd20344f66b0e1a15a7064041bf0aexeLummaStealer
2025-06-11 03:42:09ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-06-11 01:55:56ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-06-10 21:34:38ff8f729eb7a69bee300d0fbf2b5e1a584b4377fe63ab8df1ee92b4b336eb5059exe  
2025-05-18 21:26:32796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-05-18 21:13:14796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-05-18 21:08:50796ce3e06bc10916427b847a1b6c2f1eaa9904f95db66e35c28cebec34efc9c5exeLummaStealer
2025-04-21 17:18:166f4d7ea56afebf58bad06224c451abb940024964eda927eb1431a451051d7229exe  
2025-04-19 00:35:291ea0aee1d1d90e3f79f998774f51f6daaed9b90df878abe1fd699b61ed4d3003exe 
2025-04-17 19:15:10d3fd1b9c5e60f103948c8c6e2c5bbf5b857100d95271f54a8cd4f6c694b854a5exe  
2025-04-12 14:08:314ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-04-12 13:56:264ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-04-12 13:54:384ef46582ae95f961c0a0af8262de20681d9fc34ab18ead54a634448c077fd82dexe LummaStealer
2025-03-24 00:44:118c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-23 21:40:118c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-23 21:12:518c0b11ccc08ca9295f15cc23733ce76f88ccb51f06435f29c32ebd200775118bexeLummaStealer
2025-03-18 12:03:07b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-03-18 12:03:07b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-03-03 10:12:55b80b32ff1d730cfc947db68a4fc546576195bf302d1a05eee31b988fd53ea132exe LummaStealer
2025-02-17 17:46:0112b096048be2cca3f61e8fe031efa942faf8f4c31cbafe76953b744537275aceexe LummaStealer
2025-02-14 14:53:058bc4c1e92cfffe6d52dd7f5c65263e24dbc7bc470dbf631e782afd5e90ef5ee3exe LummaStealer