URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: biz9holdings.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-05-21 05:44:05 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-09 05:32:38 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2020-05-21 05:44:07 159.65.99.182Not listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-06 05:18:04http://biz9holdings.com/PROFORMA/svr9czuzvAa8NT...Offline404KeyLogger exe Matiex gorimpthon
2020-07-30 06:35:12http://biz9holdings.com/pi/aG7u8kaVGsbct6d.exeOfflineAgentTesla ext exe gorimpthon
2020-07-29 14:56:35http://biz9holdings.com/pi/mY29HUcXmsvxR58.exeOfflineAgentTesla ext cocaman
2020-07-16 05:52:23http://biz9holdings.com/pi/tkcrypt.exeOfflineexe gorimpthon
2020-07-08 08:59:05http://biz9holdings.com/INVOICE/M.exeOfflineAgentTesla ext JAMESWT_MHT
2020-07-08 04:50:07http://biz9holdings.com/INVOICE/6ibuF2KjMM0Dc7b...Offlineexe Formbook ext gorimpthon
2020-07-07 05:31:11http://biz9holdings.com/INVOICE/crypt1.exeOfflineexe Formbook ext gorimpthon
2020-06-29 11:46:05http://biz9holdings.com/INVOICE/4IDeThF102o6ePW...OfflineAgentTesla ext exe gorimpthon
2020-06-27 20:09:05http://biz9holdings.com/INVOICE/eER8H4h9QVFZRP1...Offlineexe Formbook ext abuse_ch
2020-06-25 09:43:12http://biz9holdings.com/INVOICE/DxjCPAmIM5TrCZo...OfflineAgentTesla ext exe gorimpthon
2020-06-23 12:09:04http://biz9holdings.com/INVOICE/z6TECAFecAwh9m7...OfflineAgentTesla ext exe gorimpthon
2020-06-19 06:55:35http://biz9holdings.com/INVOICE/84BlTtJn8s8QeIj...OfflineAgentTesla ext exe gorimpthon
2020-06-18 05:37:10http://biz9holdings.com/INVOICE/dugN2KuknYkZuE1...OfflineAgentTesla ext exe gorimpthon
2020-06-16 05:27:46http://biz9holdings.com/INVOICE/gGMKPEr0DQtyFLF...OfflineAgentTesla ext exe gorimpthon
2020-06-16 05:26:38http://biz9holdings.com/INVOICE/9YiZAcZN1ccVGDo...OfflineAgentTesla ext exe gorimpthon
2020-06-05 07:56:19http://biz9holdings.com/INVOICE/p1adkZXI21YVnEv...OfflineAgentTesla ext exe gorimpthon
2020-06-03 06:40:36http://biz9holdings.com/INVOICE/fSkC7alCwLuMclB...OfflineAgentTesla ext exe gorimpthon
2020-05-29 05:04:25http://biz9holdings.com/INVOICE/rcgxkaif.zx1.exeOfflineAgentTesla ext exe gorimpthon
2020-05-27 07:50:22http://biz9holdings.com/INVOICE/qcmdpmld.0oy.exeOfflineAgentTesla ext JAMESWT_MHT
2020-05-21 05:44:07http://biz9holdings.com/INVOICE/ymjm224c.1kg.exeOfflineAgentTesla ext exe gorimpthon

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-06 05:18:047e776e49abe49ee0be27a1b490353f4473694eea874cf5daa6eff2f637030ae6exeMatiex
2020-07-30 06:35:127c0886ce75459bea4b08f95a82f88f101247b7baf66b44f930e46d111240542fexeAgentTesla
2020-07-29 14:56:35971a10fea7ff499e3016409dc10be37d603eac700a6d17302547e4ac44849b43exeAgentTesla
2020-07-16 05:52:23b342a203e496b6bcffabf00c11eb5c2e7ee7dc8d53a7476ac7df7f219ceea9f2exe  
2020-07-08 08:59:056969a5c42b29f9bcb30766e666b617523fe8515b71affd16bfc0874f75c660c2exeAgentTesla
2020-07-08 04:50:07f11bf0f5b97161b5d27b4cbbc02fae52957df15646513874df10bc06d1d4e5dfexeFormbook
2020-07-07 05:31:116934eb93d7b5e16de0687da48a001b95c84f2b741e3e8775c8e32dcb70cf5b13exeFormbook
2020-06-29 11:46:050583542d7b4606a3a7aa7ff774f7d849ee2e287697fc2ecd45d1df6332b907d9exeAgentTesla
2020-06-27 20:09:052e96f7a6b4dd1d5251af4962a9028aac90c2ceb282495018c2d879ebf583f9eaexeFormBook
2020-06-25 09:43:1282d74ca041ad8b450852b4b5e741fbcd43e9b253d4706350ae8fce91b760a476exeAgentTesla
2020-06-23 12:09:03a7b8bcd6f7cc705aed8441cb520d1796dbc16eb4293842c32487feaaa71826fbexeAgentTesla
2020-06-20 05:43:23d6ae7bc77d3e39c1895fbb0f3cbdf0cc7fbcf52595781bda7d6dc4411e24c451exeAgentTesla
2020-06-19 14:43:3249f8a53df63b928f15cf73f136aa4da17d47456f15a875ec68f6441f0ab476dbexeAgentTesla
2020-06-19 06:55:354e1890b2239ee2ce68cbc7e17ea512249bf8ad112391867e10f40de4abc1c094exe AgentTesla
2020-06-18 05:37:10bf0aaab2dca6f5906fb32a2940f19b72daa6c6b390a468fe50a8c761f0dd2fa6exeAgentTesla
2020-06-16 05:27:46e901650379e32b8f6d0fadeba74ea0b64f61faf520bf611cd5c4f99694ee11cfexe AgentTesla
2020-06-16 05:26:381c1a0994d1ce6d60e9a7f8c7760478d96839c668a1d9cd7607cdc99ba1dbece2exe  
2020-06-05 07:56:19064503ab3a3c2643c6a841186e708c797ece10dcaf99f95dd8166ac7d6a01887exeAgentTesla
2020-06-03 06:40:36e29988f43bab196b6eefb52f6a8f115db7f9ff661da13fa832574ece92ecd93eexeAgentTesla
2020-05-29 05:04:25fba34c7dafedbf6ebaa42aa59fa92ae837660e58ce4cdaced6ffd554aa93f589exeAgentTesla
2020-05-27 07:50:22238c9a018dbce6149172fadd2b55baac36b4f6abf2847cc5f9f0fa6d31b4ad41exeAgentTesla
2020-05-21 05:44:077e6e816dbbc22c332a1abb111dd3ffee00bf301aba6af9343b4caf78be3d9a35exeAgentTesla