URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: dexpsystem.com
Domain registrar:Namecheap -
Domain registration date:2022-06-27 14:29:44 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-08-03 08:27:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-07-14 00:27:25 199.59.243.224Not listedAS16509 AMAZON-02- USno
2023-07-29 01:59:56 172.233.218.191hickory02.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2023-06-27 17:26:23 13.248.148.254aba1c1ff9d2ec5376.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-06-27 17:26:24 76.223.26.96aba1c1ff9d2ec5376.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-06-30 04:36:51 45.79.244.20945-79-244-209.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2023-06-28 08:49:44 199.59.243.223Not listedAS16509 AMAZON-02- USno
2022-08-03 08:27:04 146.70.24.168Not listedAS9009 M247- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-08-03 08:27:05https://dexpsystem.com/load/OneDriveUpdate.exeOfflineexe zbetcheckin
2022-08-03 08:27:05https://dexpsystem.com/load/update.exeOfflineCobaltStrike ext exe zbetcheckin
2022-08-03 08:27:04https://dexpsystem.com/load/shell.exeOfflineCobaltStrike ext exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-08-03 08:27:0550276571b60c05a68976baa27cf72ee5e5099e4528104281b7fbc8626ece0360exe 
2022-08-03 08:27:05a2d546749333d57f7370f528e63ab3b688f72b2b33fb33bdbcab494efc766bd1exeCobaltStrike
2022-08-03 08:27:043ae4fa96ff3527bf4ea380cbcab19b7e9b0d77c3596d08f74b18b7b843ead231exeCobaltStrike