URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | bofphosalf.net |
|---|---|
| Domain registrar: | Hostinger ![]() |
| Domain registration date: | 2022-06-17 20:41:18 UTC |
| Abuse complaint sent to registrar: | Yes (2022-06-19 17:41:02 UTC to domains{at}hostinger[dot]com) |
| Domain registry: | VeriSign Global Registry Services
![]() |
| Abuse complaint sent to registry: | Yes (2022-06-19 17:41:02 UTC to info{at}verisign-grs[dot]com) |
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Not blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2022-06-19 17:38:03 UTC |
| Total malware sites : | 4 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 4 (100%) |
| A record(s) observed : | 4 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-06-19 10:47:07 | 35.186.223.180 | 180.223.186.35.bc.googleusercontent.com | Not listed | AS396982 GOOGLE-CLOUD-PLATFORM | US | no |
| 2022-07-27 20:17:33 | 194.195.211.26 | 194-195-211-26.ip.linodeusercontent.com | Not listed | AS63949 AKAMAI-LINODE-AP | US | no |
| 2022-06-19 17:38:05 | 31.220.110.233 | Not listed | AS47583 AS-HOSTINGER | SG | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-06-19 17:39:06 | https://bofphosalf.net/Server/Files/Eiybe.exe | Offline | AsyncRAT | |
| 2022-06-19 17:38:08 | https://bofphosalf.net/Server/Files/Ifdnxbsr.exe | Offline | exe freemaple XFilesStealer | |
| 2022-06-19 17:38:05 | https://bofphosalf.net/Server/Files/Server.exe | Offline | exe freemaple njRAT | |
| 2022-06-19 17:38:05 | https://bofphosalf.net/Server/Files/Loader.exe | Offline | exe freemaple Smoke Loader |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-06-19 17:39:06 | 1525076c87558a452430e1a867c8e889f0f15fc658162debd2cd29c617b372c7 | exe | AsyncRAT | |
| 2022-06-19 17:38:08 | ca0331ec9c8eb2e67a05a69b85820325991ddc73eb82fb24be527922cb1e3ba1 | exe | XFilesStealer | |
| 2022-06-19 17:38:05 | eb4066563f3540e203ce15ad3dc044ad55de9c92542ae6808dbb825b0d048d46 | exe | njrat | |
| 2022-06-19 17:38:04 | c40f8e186ff9888631bb02a63bcc994e16ab2c3c99150e5b4fea614469ab369b | exe | Smoke Loader |


SG