URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-06-28 20:25:55 | 199.59.243.228 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2021-09-30 11:28:40 | 172.105.157.192 | 172-105-157-192.ip.linodeusercontent.com | Not listed | AS63949 AKAMAI-LINODE-AP | US | no |
| 2021-02-05 05:08:12 | 18.235.92.123 | ec2-18-235-92-123.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2021-01-25 16:30:50 | 157.52.211.137 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2021-01-05 06:27:58 | 104.148.41.8 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2021-01-04 15:25:07 | 185.243.215.105 | no-reverse-yet.local | Not listed | AS202448 mvps | SE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-01-04 15:25:07 | https://www.comercailizadoracali.com/JGJFhvddcd... | Offline | exe Loki |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-01-05 18:34:30 | 4a634d4fa5c7b6efef3970d877fd07e64697af488f137318f01dd9b71c608014 | exe | Loki | |
| 2021-01-04 15:25:06 | 73875abb9bb12e00127a2524fb8cdf040f205752ecf370068435d5fc0231e4d0 | exe | Loki |
US
SE