URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: deviltelegram.000webhostapp.com
Domain registrar:Hostinger -
Domain registration date:2016-05-11 13:34:12 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-01-10 13:58:06 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :251

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-01-11 05:45:12https://deviltelegram.000webhostapp.com/A.exeOffline32 exe Loda ext zbetcheckin
2024-01-11 04:53:06https://deviltelegram.000webhostapp.com/Santaa.exeOffline64 AgentTesla ext exe zbetcheckin
2024-01-11 04:14:07https://deviltelegram.000webhostapp.com/G.exeOffline32 exe predator ext zbetcheckin
2024-01-10 13:58:08https://deviltelegram.000webhostapp.com/santa.exeOfflineDarkCloud exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-11 07:14:066e36d48c1c2132e2f2069bc973a20e4235c6761e237051b31b3558a4df938525exe  
2024-01-11 05:45:12007d4a581f70c7d0a86307123df5d769c3d948dd9b7d5c4ec3b274f2b0bf3647exeLoda
2024-01-11 04:53:06974b705980668b3d9fd809501c581d7961db4a43304826edf136764c789a28b1exeAgentTesla
2024-01-11 04:29:12873546478ec547e4e82af18fa5004c67794141d9cb98e79a4ff84c86a6c6aeb8exePredator
2024-01-10 13:58:08f1f32b6e13d2ee1678899aab184161b51b0c06df57719a85f9be5a8823c604b6exe DarkCloud