URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: androidmedallo.duckdns.org
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-21 08:21:05 UTC
Total malware sites :10
Online malware sites :0 (0%)
Offline Malware sites :10 (100%)
A record(s) observed :168

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 15:34:45 192.169.69.26sinkhole.hyas.comNot listedAS27323 SERVERSTADIUM- USyes
2022-05-31 00:39:04 46.246.12.21c-46-246-12-21.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-09-20 13:53:15 46.246.26.12c-46-246-26-12.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-12-31 16:41:56 46.246.84.2c-46-246-84-2.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-26 08:33:55 46.246.84.18c-46-246-84-18.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-08-08 21:04:44 46.246.84.8c-46-246-84-8.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-08-05 16:05:52 46.246.80.12c-46-246-80-12.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-12-22 17:39:59 46.246.80.17c-46-246-80-17.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-24 16:53:10 46.246.82.19c-46-246-82-19.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-10-06 12:54:13 46.246.4.2c-46-246-4-2.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-21 08:28:46http://androidmedallo.duckdns.org/Claro%20Secur...Offline JAMESWT_MHT
2021-07-21 08:21:56http://androidmedallo.duckdns.org/Claro%20Secur...Offline JAMESWT_MHT
2021-07-21 08:21:41http://androidmedallo.duckdns.org/cgdifn.msiOffline JAMESWT_MHT
2021-07-21 08:21:37http://androidmedallo.duckdns.org/CGDIFN.exeOfflineLodaRAT JAMESWT_MHT
2021-07-21 08:21:31http://androidmedallo.duckdns.org/Corona%20App.apkOffline JAMESWT_MHT
2021-07-21 08:21:21http://androidmedallo.duckdns.org/Win%20defende...OfflinenjRAT ext JAMESWT_MHT
2021-07-21 08:21:16http://androidmedallo.duckdns.org/Winserver.exeOfflinenjRAT ext JAMESWT_MHT
2021-07-21 08:21:14http://androidmedallo.duckdns.org/done.exeOfflinenjRAT ext JAMESWT_MHT
2021-07-21 08:21:10http://androidmedallo.duckdns.org/YJHLZX.pyOffline JAMESWT_MHT
2021-07-21 08:21:08http://androidmedallo.duckdns.org/Winver.exeOfflinenjRAT ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-07 13:32:09bce1cfbca7748bc0ff26b042668feddb6f4db2f44e10637b781cfe2394ff6414exe 
2021-10-02 00:18:34bd5fa7ccde2dbc145685b36d66c3c6161e7e780308bd6ec29666139908e7db26exenjrat
2021-09-15 16:25:3951324ce0d6bc7c8668dea9b0bcc31048038723480ca16be17e6234a7cc88c391exe njrat
2021-08-26 20:56:07ff409e50aa3473d308b7e5d6fbcb9369a7811f7d0f6700b7f1494834db9450d9zip  
2021-07-30 22:34:24d2e347f7ecbcb94a4fe2e0ea86f92d0f60321be94441265b97f0e0b212c0efbcexenjrat
2021-07-29 20:32:32989a832dd6395528e5373e6fd04432a48843c299b53e8aade6142a6fee6dec94exenjrat
2021-07-21 08:28:461d3351293492090c589ad39ec03fc265f44d96fa45d5bd451a446d311ad5a18azip 
2021-07-21 08:21:55e1b46d3d5cb232880efd189482c49882178db717994d3f3663dfe4eca843bfa0zip 
2021-07-21 08:21:41d1ae3ed0e65a3e85becdaea040af72e64f84aaf2e97dd62ba55639a81265d46dmsi 
2021-07-21 08:21:3779d3666b7a0fa6f7497eb4675b1ca9c550f8cdbf932f4410f1b8feb8d1e31d49exeLodaRAT
2021-07-21 08:21:31d6cf06cd34f50317131591268d23ef266c01bf3f758893568f10204825cc3369unknown 
2021-07-21 08:21:21319b6b852006b89fe1aca8715cd3720e9a15ca2176ea256b9fd93557130d4e79exenjrat
2021-07-21 08:21:16a96ae0b647e51ed4a6ee91306db79ec60d4f4c34b341391f7e806e7726744cf9exe njrat
2021-07-21 08:21:143582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4fexenjrat
2021-07-21 08:21:10c91814a20e581ed58e22d44f441c195d471657ff36e97a4934abe9c603c16dfaunknown 
2021-07-21 08:21:084f0e5aa77c0e9894c311e8ba4daadeeb5d8b7a6f583cf087a5c90547cfe54708exenjrat