URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | epsys.ro |
|---|---|
| Domain registrar: | n/a |
| Domain registration date: | 2007-09-13 00:00:00 UTC |
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Blocked |
| AdGuard : | Not blocked |
| Cloudflare : | Not blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2024-09-11 13:40:05 UTC |
| Total malware sites : | 6 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 6 (100%) |
| A record(s) observed : | 1 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2024-09-11 13:40:07 | 89.42.218.72 | server-0355.whmpanels.com | Not listed | AS205275 ROMARG | RO | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2024-09-17 16:31:10 | https://epsys.ro/we/B.exe | Offline | AgentTesla | |
| 2024-09-17 16:31:09 | https://epsys.ro/we/ord.exe | Offline | Formbook | |
| 2024-09-17 16:31:08 | https://epsys.ro/we/kin.exe | Offline | AgentTesla | |
| 2024-09-17 14:41:06 | https://epsys.ro/we/DEMONCODER.dll | Offline | dll | |
| 2024-09-17 14:41:05 | https://epsys.ro/we/euro.exe | Offline | exe Formbook | |
| 2024-09-11 13:40:07 | https://epsys.ro/we/bin.exe | Offline | Formbook |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-09-17 16:31:10 | 5711154a5a3b1fddef167b688eb44716d120b1b6a21d67449bf49d77ce33059e | exe | AgentTesla | |
| 2024-09-17 16:31:09 | f8281ab4854afae09b60e2a66953587e0c5459d079bb1b307ef29a28e5f1be0c | exe | Formbook | |
| 2024-09-17 16:31:08 | e13e7d8d8aad930b652ff5528e22fe505495688f7ffb27eeb1a1f80d0f5c5fd3 | exe | AgentTesla | |
| 2024-09-17 14:41:06 | c0ae10c66edf8c07a100b3dbd62d1c5f3266a16b12a32f41faa69b4af1b6790a | dll | ||
| 2024-09-17 14:41:05 | d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9 | exe | Formbook | |
| 2024-09-11 13:40:07 | b120727ce78f5de370b91e1f0016740d3e9d57a105b54c4e265e94db40c045ef | exe | Formbook |
RO