URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 3.zhzy999.net |
|---|---|
| Spamhaus DBL : | Abused domain (botnet C&C) |
| SURBL : | Blocked |
| Quad9 : | Blocked |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2019-05-06 04:27:01 UTC |
| Total malware sites : | 1 |
| A record(s) observed : | 31 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-08-31 02:30:02 | 45.61.170.158 | powered-by.atomicnetworks.co | Not listed | AS14956 ROUTERHOSTING | US | yes |
| 2021-07-20 20:55:43 | 209.126.123.11 | static-ip-209-126-123-11.inaddr.ip-pool.com | Not listed | AS30083 AS-30083-US-VELIA-NET | US | no |
| 2021-04-30 18:25:37 | 103.224.212.219 | lb-212-219.above.com | Not listed | AS133618 TRELLIAN-AS-AP | AU | no |
| 2021-05-10 22:04:11 | 70.32.1.32 | ip-70.32.1.32.hosted.by.gigenet.com | SBL698544 | AS32181 ASN-GIGENET | US | no |
| 2021-02-17 10:04:48 | 91.195.240.12 | Not listed | AS47846 SEDO-AS | DE | no | |
| 2020-12-07 22:38:14 | 103.44.251.241 | Not listed | AS4816 CHINANET-IDC-GD | CN | no | |
| 2020-11-29 20:50:10 | 203.98.96.183 | Not listed | AS137125 NETSAT-AS | IN | no | |
| 2020-08-03 18:23:38 | 203.98.96.180 | Not listed | AS137125 NETSAT-AS | IN | no | |
| 2020-08-02 13:03:19 | 59.188.7.109 | smtp3.asiaproline.com | Not listed | AS17444 HKBNESL-AS-AP | HK | no |
| 2020-05-31 23:01:31 | 5.79.80.4 | Not listed | AS60781 LEASEWEB-NL-AMS-01 | NL | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-05-06 04:27:06 | http://3.zhzy999.net/images/n.exe | Online | exe |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-08-31 19:19:25 | 39b20380ab6ebdcea2024d9f49e03fc145d01a5c998319433402a703253f3d8d | exe | ||
| 2026-08-31 02:30:02 | 73475a4bda17b83de8cd6d13c6bf812bdb7930dfd6bffbb96701ab7eca5ee83f | exe | ||
| 2020-04-02 19:06:04 | 92bd9732f75f5039992d37f9f72008ad260e4d0dc6cc31e422ccffca3a50ea0f | exe | ||
| 2020-03-29 19:52:21 | 84e917ee7c99d8d511237b523456769124ce402d4b539f4f03b397ffd844bcaf | exe | ||
| 2020-03-12 09:07:42 | a115a21ac2ec4da060777c6ac92968c237d76c7dcb2b6fe10ee9a61fa3b597b7 | exe | ||
| 2020-02-02 12:09:51 | 54f7690820302c4ed95b0c16d49a3135bc1ca32db6e8bf60943b218bbc744e0a | exe | ||
| 2019-10-07 02:38:16 | 4ca5db8c401f152b4f80c4b0245edfb8256c6c8216f132aae17fdbcf1552b813 | exe | ||
| 2019-10-04 04:45:49 | 9a946132203c1da1b379c4e04b9f9414d02a869e93dfa271224ed2731239d308 | exe | ||
| 2019-05-06 04:27:06 | 51b3d6b1add70e3b14c8ea224dd804467523a4fe2360021576f559761331a084 | exe |
US
AU
DE
CN
IN
HK
NL