URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: andrewjohnson.top
Domain registrar:NICENIC -
Domain registration date:2023-08-15 09:41:03 UTC
Abuse complaint sent to registrar: Yes (2023-08-21 15:41:01 UTC to support{at}nicenic[dot]net)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2023-08-21 15:41:01 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-08-21 15:36:04 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-08-24 09:19:56 193.108.114.89Not listedAS214822 MTFINANCE-AS- RUno
2023-08-21 20:14:44 195.58.51.86SBL655141AS214822 MTFINANCE-AS- RUno
2023-08-21 15:36:06 45.87.247.123Not listedAS212165 kvmka- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-08-21 15:36:06http://andrewjohnson.top/calc.exeOfflineburix dropped-by-PrivateLoader MarsStealer Stealc andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-08-25 15:50:5605564e0d6fe1ae0a70943353d51dd0bc19a47ec896ee36533632d34b9f557a90exeStealc
2023-08-25 13:29:0713ce643b4ba34757d8d5fa9e071308fbb0120bd467588a4b3b7e6181275af6e7exeStealc
2023-08-25 09:32:451b0da8603f31103a5d90152c983ddd534e128abed1901fe5debb660c0bb6ecceexeStealc
2023-08-25 08:37:00480afef1f95b2130b1dfceafb7f5639d962c9957e003863dc30f6f7ed40ee79dexeMarsStealer
2023-08-25 05:14:51d8e82dd460b3e9538fcef64e56b5348fa777e5d73dc1d61d92fd49e7e7e7305bexeStealc
2023-08-24 23:36:147f175ae66302a4dcf074319d0d89220570a8963d43395d3cf61b3faaab3fe0b1exe Stealc
2023-08-24 22:25:44c4cc355c8e3bc52a53f43f85c606d824b607fd91ffff384393bc7f99823bb219exe Stealc
2023-08-24 21:03:279e9898215c57e4dd2d5e9e34e6bd3eef1f1594ccb17ef2f1e4c6f90481044a18exe MarsStealer
2023-08-24 10:37:46715821d03d18bb8dab9435aa68a6507532630ed3252dcbf76316a2e8ea228be8exeMarsStealer
2023-08-24 09:19:56cc8b9741a463bf30fac6365f6fa6aaf48a63e5a0931bc0eba57cf24f40e7b1bcexe MarsStealer
2023-08-24 07:58:29bff8580b564b68ff541a2f597715b69a2bd9373529eb6278c2e6fcf321fb50bcexe Stealc
2023-08-24 03:19:566c0089de11a289ffeb0a44db2d5dae12a3684a2f337fd7b49af6e08bb615b76cexe Stealc
2023-08-24 00:09:44c12b55961d4542e07063d063d7f9cc6f5cc6c6b0c388b6565f1bb56fc19662f4exe MarsStealer
2023-08-23 20:58:47651802363bfec1ee27819b8a7c2b48c68254ba6f75fb48c2b168c779615651f7exeMarsStealer
2023-08-23 19:59:3402b046423b0773b5b5a118ef16da6c55aac47ee3c6d2e861b9a8aaaedc248402exe Stealc
2023-08-23 16:43:31cbc45ecc527566af8060f7dbaea341962df2350423dbc3c674c27dcf5b7d3892exeStealc
2023-08-23 12:57:182df44897eabeabd3cdcbe54374aa6e29c998e9667090a33a3955c7a803c202a9exe MarsStealer
2023-08-23 11:44:260ae1d3ff00b7076d442781a34a881890ff117897c6d889247131eb18f0581f72exeStealc
2023-08-23 07:46:5301e358f96191d56edb8b11009728fa9ef69ea6628bb86a1c49dfb3122d1a9372exe MarsStealer
2023-08-23 05:12:29508636b6c60753fad23295328180bf3b2c003437fdabc24a84f6d283fd3d96faexeStealc
2023-08-23 00:29:15d25fce3502958abc307965d62545c45b578a23d7d7878ffcaa0f65ea83068cb3exeStealc
2023-08-22 20:34:32c0d4f11f46c6d39aec1956a0703d1af2f0cfef9becffc8c73be712558dbbdf21exeStealc
2023-08-22 18:11:22e66d15b8ea22a42469fc8f51aee5cb9a5a72360a5a14044fd779182541e419abexe Stealc
2023-08-22 17:21:51efe76e209a9575bc73aa11a6c35be706087fdc696645821c5959a4f445540e3dexeStealc
2023-08-22 14:24:423a0540a3db9219f4f54fe07ce1777f8c1087b5ed126e5a404935a925e367593cexe MarsStealer
2023-08-22 13:12:008320b1984cd007f2e819d2572382e0d231feae3b91ec2d30163665aa1295cdc5exeStealc
2023-08-22 10:34:057b573396a695127f4df05f183d2efc0e107115a24ccc0458b900e02eaeca2082exe MarsStealer
2023-08-22 07:56:27ee29cc3108d7e380d887d223808f4254eb098bbaffc4639b5988261c8146eb80exe MarsStealer
2023-08-22 05:08:298c3379cd31478527d1d0405a836a59220a3cdd3135661b40d30e1ed509c34993exeStealc
2023-08-22 00:48:360044ef132e6113d649ef27f1864c350ba16cb7ad5b4257fdb24a8cf9ec670310exeMarsStealer
2023-08-21 23:56:14151d0f671b56cdeb1f7a2d3cd28160b2e766517fd056e5da4e32110f800a46b9exe MarsStealer
2023-08-21 21:42:412a8c4927c673ae53fa0b99c0f2e8dce3b09ea7f6ea9855c4140f198b9789f916exeStealc
2023-08-21 20:14:4334eba2859581b7326e6494e229e992053d0999e074921f95fe55c904efa485ecexe MarsStealer
2023-08-21 19:08:06c0766ce30c875a6a40e50ca428861ce55a6c3133bc8e4f96feabe7de07bb4942exe MarsStealer
2023-08-21 18:08:34ec0583aa7c0fc4ef8363a51b2c56a3ff5b602fa494325525d2a7c27b0775bea8exe MarsStealer
2023-08-21 15:36:066321cb7ca4e2ed3b0a5d3472556bfbe959343e0f7a971896189a8a1e7a467370exeStealc