URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cmontealban.edu.mx
Domain registrar:Akky Online Solutions -
Domain registration date:2015-07-13 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-06-14 09:02:04 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-06-14 09:02:13 174.136.52.223svgp267.serverneubox.com.mxNot listedAS17378 AS17378- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-06-14 09:02:13https://cmontealban.edu.mx/eb/OfflineBB32 geofenced js Qakbot ext Quakbot ext USA Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-06-14 13:16:131c944f78f45c258901d24b07361415399f05ba3a81f7961ce886a489fc4754d6js Quakbot
2023-06-14 11:09:30dfe99e49909839abaa99142b09b1e8eaf4d5ceb9e5880e75b045fc2c805c4f7ezipQuakbot
2023-06-14 09:59:52b4a8b583d41a21ff7972851dd6f0f38096101909cba59db3f204f0b9a19cf146js Quakbot
2023-06-14 09:02:0725ae3e1501445de4378eafc511e7ccc1ce8097bf4ca20e7faa59afb364c3b236js Quakbot