URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: chfourmndyanotherwak.dns.navy
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-19 06:29:03 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-19 06:29:08 103.141.138.133Not listedAS135905 VNPT-AS-VN- VNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-19 06:29:08http://chfourmndyanotherwak.dns.navy/chnsfrnd2/...Offlineexe Formbook ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-19 19:36:152f4c024e90b8fdb3077395f4b7b59c38d1feca1e8477636a8dfe4ab0b0da77e0exeFormbook
2021-01-19 08:58:37d433e7ca5197ed83d851161b45aa94ae8b469a2c711b7a327d749c32279785f5exeFormbook
2021-01-19 08:20:578fe13da45a5732ae42c27687b9cf9105a3f2028857729bdfbe3ae31514a6b298exeFormbook
2021-01-19 06:29:089787e886d7536b9343db7b8b78a9f87f5177b5d11460130d2aced11ccb44de8fexeFormbook