URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host xzd.197946.com.

Database Entry


Host:xzd.197946.com
Spamhaus DBL:Not listed
SURBL:Not listed
Firstseen:2019-01-26 18:00:05

IP addresses


The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-04-09 15:13:54122.225.34.185Not listedAS58461 CT-HANGZHOU-IDC No.288,Fu-chun Road- CNno
2019-04-09 07:42:46140.249.60.232Not listedAS58541 CHINATELECOM-HUNAN-XIANGTAN-MAN Xiangtan- CNno
2019-04-08 04:26:19122.246.20.206Not listedAS136188 CHINATELECOM-YUNNAN-DIQING-MAN Diqing- CNno
2019-04-05 02:37:0759.63.247.228Not listedAS134238 CT-JIANGXI-IDC CHINANET Jiangx province IDC network- CNno
2019-04-05 02:11:4058.218.208.8SBL438380AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-04-04 22:52:13140.249.61.18Not listedAS58541 CHINATELECOM-HUNAN-XIANGTAN-MAN Xiangtan- CNno
2019-04-04 20:06:07122.225.34.186Not listedAS58461 CT-HANGZHOU-IDC No.288,Fu-chun Road- CNyes
2019-04-04 12:15:49122.228.95.180Not listedAS134771 CHINANET-SICHUAN-CHENGDU-MAN CHINANET Sichuan province Chengdu MAN network- CNno
2019-03-31 12:39:2158.215.145.148SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-30 18:03:36121.207.229.202Not listedAS133774 CHINATELECOM-FUJIAN-FUZHOU-IDC1 Fuzhou- CNno
2019-03-24 22:49:26140.249.61.73Not listedAS58541 CHINATELECOM-HUNAN-XIANGTAN-MAN Xiangtan- CNno
2019-03-24 21:15:05140.249.60.230Not listedAS58541 CHINATELECOM-HUNAN-XIANGTAN-MAN Xiangtan- CNno
2019-03-24 15:38:3958.215.145.137SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-23 18:20:40222.186.49.226Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-23 14:28:4958.215.145.134SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-23 10:49:49122.228.95.185Not listedAS134771 CHINANET-SICHUAN-CHENGDU-MAN CHINANET Sichuan province Chengdu MAN network- CNno
2019-03-23 00:40:00222.186.49.221Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-21 16:15:0758.215.145.185SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-18 11:24:35122.228.95.184Not listedAS134771 CHINANET-SICHUAN-CHENGDU-MAN CHINANET Sichuan province Chengdu MAN network- CNno
2019-03-17 17:40:3559.63.247.230Not listedAS134238 CT-JIANGXI-IDC CHINANET Jiangx province IDC network- CNno
2019-03-17 12:10:34122.225.34.236Not listedAS58461 CT-HANGZHOU-IDC No.288,Fu-chun Road- CNno
2019-03-16 11:32:4358.215.145.152SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-15 04:15:2158.215.145.147SBL306879AS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-13 19:50:5558.218.208.12SBL437239AS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-03-13 07:40:07222.186.49.225Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-12 10:58:23222.186.49.220Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-06 11:49:48222.186.49.222Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-03-05 17:11:29222.186.49.223Not listedAS23650 CHINANET-JS-AS-AP AS Number for CHINANET jiangsu province backbone- CNno
2019-02-27 17:54:11122.228.95.139Not listedAS134771 CHINANET-SICHUAN-CHENGDU-MAN CHINANET Sichuan province Chengdu MAN network- CNno
2019-02-24 09:14:51175.6.235.232Not listedAS63838 CT-HUNAN-HENGYANG-IDC Hengyang- CNno
2019-02-22 22:47:47125.76.247.211Not listedAS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-02-21 07:21:4345.253.17.217Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.216Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.215Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.214Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.213Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.212Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.211Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-21 07:21:4345.253.17.226Not listedAS7497 CSTNET-AS-AP Computer Network Information Center- CNno
2019-02-20 18:12:52171.111.154.207Not listedAS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-02-20 16:22:49183.57.82.230Not listedAS58543 CHINATELECOM-GUANGDONG-IDC Guangdong- CNno
2019-02-20 14:33:2236.102.212.97Not listedAS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-02-20 13:44:2261.184.215.225Not listedAS4134 CHINANET-BACKBONE No.31,Jin-rong Street- CNno
2019-02-19 23:36:47119.36.228.227Not listedAS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone- CNno
2019-02-18 08:09:0645.116.210.101Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno
2019-02-18 08:09:0645.116.210.95Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno
2019-02-18 08:09:0645.116.210.96Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno
2019-02-18 08:09:0645.116.210.100Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno
2019-02-18 08:09:0645.116.210.102Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno
2019-02-18 08:09:0645.116.210.99Not listedAS4847 CNIX-AP China Networks Inter-Exchange- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2019-01-26 18:00:13http://xzd.197946.com/winrar-x64.exeOfflineexe Ransomware.GandCrab Clean@zbetcheckin