URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ant-ec.duckdns.org
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-21 15:06:03 UTC
Total malware sites :1
A record(s) observed :74

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-29 17:16:14 46.5.200.150ip-046-005-200-150.um12.pools.vodafone-ip.deNot listedAS3209 VODANET- DEyes
2022-02-11 08:28:12 46.246.84.3c-46-246-84-3.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-02-07 14:03:46 46.246.26.16c-46-246-26-16.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-02-05 02:53:52 46.246.26.18c-46-246-26-18.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-10-30 16:55:33 46.246.12.16c-46-246-12-16.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-28 10:12:52 46.246.80.15c-46-246-80-15.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2021-07-24 03:38:55 46.246.6.10c-46-246-6-10.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-05 11:25:47 46.246.4.20c-46-246-4-20.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-20 15:47:57 46.246.86.20c-46-246-86-20.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2022-01-15 16:42:05 46.246.26.22c-46-246-26-22.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-21 15:06:06https://ant-ec.duckdns.org/Winver.exeOffline32 exe njRAT ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-21 15:06:064f0e5aa77c0e9894c311e8ba4daadeeb5d8b7a6f583cf087a5c90547cfe54708exenjrat