URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ebie.xyz
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-13 07:59:03 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-03 13:17:58 13.248.169.48a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-09-03 13:17:58 76.223.54.146a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-09-05 19:15:44 166.117.110.61Not listedAS16509 AMAZON-02- USno
2025-09-05 19:15:45 99.83.161.153a2b7bf3398455f345.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-08-28 10:14:41 150.95.255.38Not listedAS7506 MAINT-JPNIC- JPno
2022-09-20 23:21:44 199.59.243.222Not listedAS16509 AMAZON-02- USno
2021-07-13 07:59:03 185.239.243.112ns1.20mb.nlNot listedAS212238 CDNEXT- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-19 20:33:08http://ebie.xyz/ugopoundx.exeOffline32 exe Loki ext zbetcheckin
2021-07-19 16:37:08http://ebie.xyz/quotation.exeOffline32 exe Formbook ext zbetcheckin
2021-07-19 15:13:03http://ebie.xyz/quote.exeOfflineFormbook ext xloader James_inthe_box
2021-07-14 14:54:03http://ebie.xyz/smartx.exeOfflineexe Formbook ext abuse_ch
2021-07-14 14:12:03http://ebie.xyz/mazx.exeOfflineAgentTesla ext exe abuse_ch
2021-07-13 18:56:04http://ebie.xyz/ashleybinx.exeOffline32 exe Formbook ext zbetcheckin
2021-07-13 14:36:04http://ebie.xyz/chungx.exeOffline32 exe RemcosRAT ext zbetcheckin
2021-07-13 10:55:03http://ebie.xyz/jayxz.exeOffline32 exe Loki ext zbetcheckin
2021-07-13 10:51:03http://ebie.xyz/whesilox.exeOffline32 AgentTesla ext exe SnakeKeylogger ext zbetcheckin
2021-07-13 10:47:04http://ebie.xyz/arinzex.exeOffline32 AgentTesla ext exe SnakeKeylogger ext zbetcheckin
2021-07-13 07:59:04http://ebie.xyz/catx.exeOfflineAgentTesla ext exe NanoCore ext rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-20 16:34:0604cdbb87050fa773ed542d18c1993851661cdebcd06acb6af05bd9e03d14a1c8exeAgentTesla
2021-07-20 07:06:157d05531d9460fab2b3f033c6daa0ad96f103d31cd4d743bb2543fceff24a8085exeSnakeKeylogger
2021-07-19 20:53:19c93e913c5dd5c8371f2acb548cf3761cec09e76c5b37b3cb36163142ccc45b5bexeAgentTesla
2021-07-19 20:33:08e97a4942254a12b854161a49aa1921910d93d2ea2d6af2f2ed771d7ed7d70badexeLoki
2021-07-19 16:37:0896a59a7f3a3aed504052f94d5808bfc4f42054104c955e3fe244f0b0750b48c2exeFormbook
2021-07-19 15:13:03ffdce32ce2f9c0f99abb5cff3602bcc02f3ceb4933d145fe02f650244b513a51exeFormbook
2021-07-19 14:52:061e57ec3b629e18155d01329fd7ca2947f30f7a9dbb6a60e3f5de2f0d8934ed92exeAgentTesla
2021-07-19 11:06:5351eb7e5e2034ecc3743a2bdf49627342f0cdcaf82384dc09812228618643c51cexeAgentTesla
2021-07-19 10:39:22386eba6b68ddbb34754a2d335a0b0799ce2b6979ac792c51323b8f687853fe89exeAgentTesla
2021-07-16 02:42:17eb49079f48b94e03346f8e7e2e6d90853fcadf1547ef19ae62c2d0ab9dc23460exeAgentTesla
2021-07-16 00:41:0103a5f02e2510ecf8b8990cd651cc7085e057555e8be3415e48167e73ae3aeb40exeAgentTesla
2021-07-14 14:54:03ba41a0e0bfc666b2f37abbb5fe9373d77922ea90b4f7c975e9aaaf27edec129eexeFormbook
2021-07-14 14:12:03d0638a8dd7cdd32f69d17312f76a526f025c29511dd2fd9ba7bddc51867bc912exeAgentTesla
2021-07-14 10:45:195fb2d0f98ed386069283bf30b84dc9da845b0e6e02a1411e017f90b88aea0658exe SnakeKeylogger
2021-07-14 10:07:479951d9f054be7e8c7b662ce9c2fc30b5aaf61bdc8482d7fd6e4464e4923540afexeSnakeKeylogger
2021-07-14 07:38:013e1b4bf644f36778e4b8309d78e20a37747b5945e94b33f5ba17f224e041e6e4exeSnakeKeylogger
2021-07-14 00:37:434668c19e2ba4b487bdbdb747386dd1f319fe36450d4ab5b82010a8215bbc4da1exe NanoCore
2021-07-13 18:56:04450178f7975019437a0e145934d9f99c1c4cc7be3b4ab8ab30454460447199a4exeFormbook
2021-07-13 14:36:041cbde001232b05773813dca161a55e63f8e082b7b53f900a4e235d2753bd1957exeRemcosRAT
2021-07-13 11:08:14305ff91660cc5f742e0689b4e929725c874941242ffffb85247dde1b84ca8e79exeAgentTesla
2021-07-13 10:55:030152804ad2c328b9f25b337d05f405d265d00be4630b567f5f20175abb38585aexeLoki
2021-07-13 10:51:0320099b68fc7896261434a79ffe3398f80a268118b180dce7a7af8c9b7260ec58exeAgentTesla
2021-07-13 09:19:50a5da0c0fcaf0979b3e42e3b9f8c553e33cc0de3a0c3d7d727fabda99b859d044exeNanoCore