URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: amassmodel.top
Domain registrar:NameSilo -
Domain registration date:2023-05-07 23:09:19 UTC
Abuse complaint sent to registrar: Yes (2024-03-12 07:18:36 UTC to abuse{at}namesilo[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2024-03-12 07:18:36 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-01-25 18:34:05 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-02-22 14:01:40 104.21.68.43Not listedAS13335 CLOUDFLARENETn/ano
2024-02-22 14:01:40 172.67.186.86Not listedAS13335 CLOUDFLARENETn/ano
2024-02-22 13:22:34 195.123.210.7vds1260551.hosted-by-itldc.comNot listedAS50979 ITL-LV- LVno
2024-02-22 13:26:34 195.123.241.205vds1256662.hosted-by-itldc.comNot listedAS204957 GREENFLOID-AS- USno
2024-01-26 12:54:54 188.114.96.0SBL686925AS13335 CLOUDFLARENETn/ano
2024-01-26 12:54:54 188.114.97.0Not listedAS13335 CLOUDFLARENETn/ano
2024-01-25 18:34:07 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2024-01-25 18:34:07 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2024-01-25 19:10:51 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2024-01-25 19:10:51 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-03-12 10:16:34d288e4cc3b1b09a168b8a47771e2f4296890634c9f5128a1d3bbaa97d33afd90exe AgentTesla
2024-03-12 09:15:05718bdf94dd3385b02256011e20334806a95a81c9f7e81abe8830b6a7514e8c9dexeAgentTesla
2024-03-12 07:18:074a116d875adbac028ee35274af2d72f9be5bd9b6306eff988b15341088277781exeAgentTesla
2024-03-12 07:05:0999cba0a4969c5cf818a8f6abec732cd9976ccff9c01ce07d78e67db1c030f4eaexeAgentTesla
2024-03-11 17:32:08efce051b1d799bd344d7b354e5898cccd79a0014593d2034cd6b00d01b4536f8exeAgentTesla
2024-03-11 17:15:11998b69e7dc9ccb3557e67c3dea551d5485b64b985dd7ffd06f3ae258f868a88dexeAgentTesla
2024-03-09 11:47:06aa99c07203568e2616875fcf1094ffc5225cc72cd31aa52658a3018991525c0fexeAgentTesla
2024-03-07 14:14:09202bb0c3e66d81f1a6ae9445cb73a640eba568ae43f4078739829facfc6a4a76exeLoki
2024-02-21 09:41:01e06be3822489c945623c95998caec5ed42bf81031501996861bcc8848eec4130exe NanoCore
2024-02-21 07:23:08b16c9c6b0d2c5e04fd3d3bcfb9f9a8712502b99a1fea9edf9a2ff1dd1cc8ed41exeNanoCore
2024-02-20 09:37:08f45bd2113210436961213be67da89161229752addb6f0e1596110400c0ee3bcbexe  
2024-02-20 03:20:3714639e09de7a97ffa6e96fd1157dacc19c147625b3f4e221a66a4c017f367ef1exeAgentTesla
2024-02-19 10:51:07420e895398b4c9524e17f6d65455eefcf288b239027494f705a62413496ec157exePureLogStealer
2024-02-19 10:13:10ee58fa913b4f5d0527453664b762b848404c19c23369ab6c4c893d55adbdde4bexeNanoCore
2024-01-25 18:35:10f313ed23323b609ed09075856805772adf3487d3b565429adde2b71793cb73bfexeRemcosRAT
2024-01-25 18:35:10489485f76c425b348691243b18355c39990c477483b8f2eca99d9df8225ba3f9exeGuLoader
2024-01-25 18:35:1053fb5ae6197173f165b57043a1c7460bd648d0d9d4a747e906000c6495e895e1exeAgentTesla
2024-01-25 18:34:07104ae348871545562f1f0a2712ddb88659fda045dd969affd79fbdc25fc7e2fdexeFormbook
2024-01-25 18:34:07a686d022d2c5765b4179a7d8b8af4f4aa5fa009c255d352479ff4f7f2c578b39exeRemcosRAT