URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-08-07 06:14:16 | 13.223.25.84 | ec2-13-223-25-84.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | yes |
| 2025-08-07 06:14:16 | 54.243.117.197 | ec2-54-243-117-197.compute-1.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-05-25 07:16:51 | 13.216.111.180 | ec2-13-216-111-180.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-04-30 10:28:58 | 3.94.41.167 | ec2-3-94-41-167.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-04-30 10:28:58 | 52.86.6.113 | ec2-52-86-6-113.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-05-01 01:00:15 | 3.130.204.160 | ec2-3-130-204-160.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-05-01 01:00:15 | 3.130.253.23 | ec2-3-130-253-23.us-east-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 08:38:16 | 34.205.242.146 | ec2-34-205-242-146.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-04-27 08:38:16 | 54.161.222.85 | ec2-54-161-222-85.compute-1.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-02-18 15:53:42 | 52.128.23.153 | Not listed | AS19324 DOSARREST | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-03-15 15:32:23 | https://zarabotka.janehub.com/qtpb68.tar | Offline | 10444 dll Dridex | |
| 2021-03-10 17:52:52 | https://zarabotka.janehub.com/hnmxiau.zip | Offline | Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-03-16 05:32:38 | ee264a9ac85435880323e9666bd673c0099fc8ffd3c6b5850291b98953d46169 | dll | Dridex | |
| 2021-03-15 17:48:16 | 18e884cd3d534c4cf27690ca6e6c0ac6eac9af7252322407e577e0cd372108f9 | dll | Dridex | |
| 2021-03-15 15:32:23 | a06b2dd730dbd255594c2c231e18559bf25953967580cb0f96c29e37cc4a9117 | dll | Dridex | |
| 2021-03-11 06:52:27 | e0c318312aa5ab60478f536d261449a47670f816b828d66865af418411132cb0 | dll | Dridex | |
| 2021-03-10 17:52:52 | 7c3bdd73fd2094ba07a6e2db53fae54da83a316c2138140279350946ea59641f | dll | Dridex |
US