URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: docshare.icu
Domain registrar:Webnic -
Domain registration date:2024-12-06 01:50:06 UTC
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-02-02 07:33:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-02-02 07:33:06 185.208.156.80SBL640646AS42624 swissnetwork02- SCno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-02-02 07:34:07https://docshare.icu/templates/imagesoftware/Im...Offlineexe LummaStealer opendir abuse_ch
2025-02-02 07:34:04https://docshare.icu/templates/imagesoftware/1.exeOfflineexe LummaStealer opendir abuse_ch
2025-02-02 07:33:06https://docshare.icu/templates/imagesoftware/me...Offlineopendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-02-03 18:15:50e23d5adb5b14436e7d60b3f7e8994333af77f807cdeb28ea7df43852824a7a77exe LummaStealer
2025-02-03 15:31:52b109e1eae39bf683262796857e65e71a70deb76ab500fb103a4f743d9884df32exe LummaStealer
2025-02-03 14:27:530c3d32d400410ab104b0446ecd9be7bfd63556265a2fad2edf5cec68d36aa1e1exe LummaStealer
2025-02-03 13:28:100f70ecaa27b159fec96e2a0e3a2080a186f080dd0e4416ab7f240517264056b4exe LummaStealer
2025-02-03 10:44:0707ab5f1fcaa448d0679efabd38bf4fef686f6c203588c40af888a1130ba954deexe LummaStealer
2025-02-03 09:03:1048d334a86cfc76551632483b6337278e757ce0e8b0f0086d9010bb37ae14d469exe LummaStealer
2025-02-03 05:27:076fc945523cc89d3a2f3abf600117a4abe52f4f7f7e22ecb763566c147e8e59bdexe LummaStealer
2025-02-03 04:54:183798943b9e4e28bf796e4dd28a17cb0ccca344c2b0f2473710149059e981ae84exe LummaStealer
2025-02-03 04:39:0024d72a9d0bbef0ad3c845b1fee3854f401771f3925587264bfcd36b4ddcaa994exe LummaStealer
2025-02-03 01:09:16d28c69e931b6bf364fab0116583f80a3243d12ad870d8580abe8f2cdc2ec1c7bexe LummaStealer
2025-02-02 21:45:3066e610fd6a77a7e73b5fcfbc2f741215989fc6a66d483da9805d197288a0b387exe LummaStealer
2025-02-02 20:41:01dd18b6c20deb7a5ef80c8b9a3c9e60e73e5f002422743641a02badfa66241cb2exe LummaStealer
2025-02-02 19:06:042c669ce4a14cb9a54ea4c4c9aad86c4be8ef2fa77df7515930ff588eb85adcceexe LummaStealer
2025-02-02 17:34:55bd37c06dd246a70a7f3d34e939f9d9016884c0d09fe835622c8f130b948170b4exeLummaStealer
2025-02-02 12:04:51c1e01e2b2769898b635f38646ee2481000b43f8fe5d0efa32cdc13faf6e9e31fexe LummaStealer
2025-02-02 11:47:01567e12bf3b85bf8c13d9e7deaa5f5ce636658a34d1a4f2389b6094714b26850eexeLummaStealer
2025-02-02 07:34:07d46662f5f75e5ae182f522a1e64df9bade5cdc5d7eca415062aa2af2c4b60853exeLummaStealer
2025-02-02 07:34:04ab1f110b4e24b1bf73b78324bedad261c4d28a1c6fe38e37cdd1919542efda43exe LummaStealer
2025-02-02 07:33:0403888969377783cbcb4a1613b1fa24768f91a1d91c9e13a3d62f06eb2e30e49aunknown