URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-10 17:49:49 | 8.217.99.246 | Not listed | AS45102 ALIBABA-CN-NET | HK | yes | |
| 2025-11-04 04:10:12 | 8.210.30.50 | Not listed | AS45102 ALIBABA-CN-NET | HK | no | |
| 2025-10-31 00:59:34 | 172.65.185.109 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-09-16 10:59:30 | 51.195.17.68 | ns5.expirationwarning.net | Not listed | AS16276 OVH | FR | no |
| 2025-09-17 18:05:35 | 51.161.21.1 | ns3.expirationwarning.net | Not listed | AS16276 OVH | CA | no |
| 2025-04-27 17:57:58 | 95.217.95.141 | static.141.95.217.95.clients.your-server.de | Not listed | AS24940 HETZNER-AS | FI | no |
| 2020-09-02 21:47:33 | 172.67.141.235 | Not listed | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-09-02 23:48:33 | http://www.upsara.com/images/5oal_ok.jpg | Offline | exe QuasarRAT | |
| 2020-09-02 21:51:05 | http://www.upsara.com/images/blsl_polow.jpg | Offline | exe QuasarRAT | |
| 2020-09-02 21:47:33 | http://www.upsara.com/images/vgwx_ok.jpg | Offline | exe QuasarRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-09-02 23:48:33 | 21e500dd9ca860b8ed0634fed24772cc09672b8e508ad5d52705206ce809eece | exe | QuasarRAT | |
| 2020-09-02 21:51:05 | 5b8557286deebc72d82c7b0780cc2b115b82a042d906c0c619415bc906e3b56d | exe | QuasarRAT | |
| 2020-09-02 21:47:33 | 9b28ea61b121821fb4682da4773559fce085366f263b266f4e2fb6983bc2c2ed | exe | QuasarRAT |
HK
FR
CA
FI