URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | dfd.zhzy999.net |
|---|---|
| Spamhaus DBL : | Abused domain (malware) |
| SURBL : | Blocked |
| Quad9 : | Blocked |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2019-04-23 04:52:10 UTC |
| Total malware sites : | 1 |
| A record(s) observed : | 41 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-08-29 04:54:37 | 45.61.170.158 | powered-by.atomicnetworks.co | Not listed | AS14956 ROUTERHOSTING | US | yes |
| 2021-07-30 10:19:22 | 209.126.123.11 | static-ip-209-126-123-11.inaddr.ip-pool.com | Not listed | AS30083 AS-30083-US-VELIA-NET | US | no |
| 2021-07-25 20:49:37 | 209.126.123.13 | static-ip-209-126-123-13.inaddr.ip-pool.com | Not listed | AS30083 AS-30083-US-VELIA-NET | US | no |
| 2021-08-06 16:35:41 | 209.126.123.12 | static-ip-209-126-123-12.inaddr.ip-pool.com | Not listed | AS30083 AS-30083-US-VELIA-NET | US | no |
| 2021-05-01 02:11:58 | 103.224.212.219 | lb-212-219.above.com | Not listed | AS133618 TRELLIAN-AS-AP | AU | no |
| 2021-05-09 19:53:07 | 170.178.168.203 | becrawl-show.flatreutic.com | Not listed | AS46844 SHARKTECH | US | no |
| 2021-02-18 00:10:21 | 91.195.240.12 | Not listed | AS47846 SEDO-AS | DE | no | |
| 2020-12-08 07:15:38 | 103.44.251.241 | Not listed | AS4816 CHINANET-IDC-GD | CN | no | |
| 2020-11-29 19:47:30 | 203.98.96.183 | Not listed | AS137125 NETSAT-AS | IN | no | |
| 2020-08-03 18:23:42 | 203.98.96.180 | Not listed | AS137125 NETSAT-AS | IN | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-04-23 04:52:16 | http://dfd.zhzy999.net/images/m.exe | Online | exe njRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-08-31 04:02:18 | 73475a4bda17b83de8cd6d13c6bf812bdb7930dfd6bffbb96701ab7eca5ee83f | exe | ||
| 2021-05-03 00:45:22 | 22fb221ab2307c4a7574f9a48e5503eb05c11f16d05042e58ecfbfaf16bc5025 | exe | njrat | |
| 2020-08-21 00:11:03 | a211e5ecd0d534d5231bdd53c817fb9ec571a83c5b1f8e967526c2c6a29ff2c1 | exe | ||
| 2020-04-02 18:59:29 | 92bd9732f75f5039992d37f9f72008ad260e4d0dc6cc31e422ccffca3a50ea0f | exe | ||
| 2020-03-29 19:52:30 | 84e917ee7c99d8d511237b523456769124ce402d4b539f4f03b397ffd844bcaf | exe | ||
| 2020-03-12 09:07:15 | a115a21ac2ec4da060777c6ac92968c237d76c7dcb2b6fe10ee9a61fa3b597b7 | exe | ||
| 2020-02-02 12:08:44 | 54f7690820302c4ed95b0c16d49a3135bc1ca32db6e8bf60943b218bbc744e0a | exe | ||
| 2019-04-23 04:52:14 | 51b3d6b1add70e3b14c8ea224dd804467523a4fe2360021576f559761331a084 | exe |
US
AU
DE
CN
IN