URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 16:12:25 | 104.21.54.161 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-04-27 16:12:25 | 172.67.140.90 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2022-01-31 11:27:28 | 46.20.4.254 | host-46.20.4.254.routergate.com | Not listed | AS43260 AS43260 | TR | no |
| 2021-10-27 14:31:05 | 185.132.124.244 | undefined.hostname.localhost | Not listed | AS203694 BehPardakhtMelat | IR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-10-27 14:31:05 | https://yazilim.2crankara.com/ejpcxb.zip | Offline | Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-10-28 07:37:37 | 9f6ffc83e22d683a3101641a1a1c99a0a0aa515453ed4b363696d23846a4c90c | dll | Dridex | |
| 2021-10-27 17:58:02 | a82c61523c3b3b2b5d67a90e5b5353e03855cda9bfe8ea3d5444032a575c71c6 | dll | Dridex | |
| 2021-10-27 14:31:04 | 240c19f0393b3c0bc6353b5feb1ba39d78aed4102931e4d6cf01bc8ee7979c12 | dll | Dridex |

TR
IR