URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: dlink.metallc.top
Domain registrar:NameSilo -
Domain registration date:2023-11-19 21:54:01 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-02-14 07:31:10 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-02-14 07:31:13 104.21.72.43Not listedAS13335 CLOUDFLARENETn/ano
2024-02-14 07:31:13 172.67.175.19Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-02-15 04:55:11http://dlink.metallc.top/pages/virginzx.exeOffline32 AgentTesla ext exe zbetcheckin
2024-02-15 04:55:07http://dlink.metallc.top/pages/peterzx.exeOffline32 AgentTesla ext exe zbetcheckin
2024-02-14 07:31:13http://dlink.metallc.top/pages/agodzx.exeOfflineAgentTesla ext exe Formbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-02-15 05:11:292ce0ad043e6f2c693eb6d5a2274bbf80431a9fc337d72499384acd5ef5d5ce34exeAgentTesla
2024-02-15 04:55:11aa8b2ca063172cd14a6328d7385e8ebe4367f365d86eb70386bc4d6b58ed0313exeAgentTesla
2024-02-14 10:03:5742b875ba2d7d655249fb6a50f8106b7070fcba963a9030f72558b1632e0c6a6cexeFormbook
2024-02-14 07:31:13bf2a302fc39335729896cb7c2dd05e87f2e55993801e19e43afdc094ba735ed1exeAgentTesla