URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | fallaeltro.es |
|---|---|
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Not blocked |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Not blocked |
| OpenBLD : | Not blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Blocked |
| Firstseen: | 2024-09-11 05:27:03 UTC |
| Total malware sites : | 7 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 7 (100%) |
| A record(s) observed : | 1 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2024-09-11 05:27:06 | 37.153.95.99 | virt3413.unelink.net | Not listed | AS60494 Unelink | ES | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2024-11-06 07:58:09 | http://fallaeltro.es/sgfdm.exe | Offline | MarsStealer | |
| 2024-09-23 11:16:09 | https://fallaeltro.es/lgrn.exe | Offline | exe LummaStealer | |
| 2024-09-16 20:17:06 | http://fallaeltro.es/vtrwh12.exe | Offline | exe Vidar | |
| 2024-09-11 07:20:07 | https://fallaeltro.es/vtrwh12.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2024-09-11 06:48:06 | https://fallaeltro.es/vth15.exe | Offline | dropped-by-PrivateLoader Vidar | |
| 2024-09-11 05:28:08 | https://fallaeltro.es/sgfdm.exe | Offline | dropped-by-PrivateLoader MarsStealer | |
| 2024-09-11 05:27:06 | https://fallaeltro.es/vhtrw.exe | Offline | dropped-by-PrivateLoader Vidar |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-11-06 07:58:09 | ec9a1bede697caba74ff4666e0317cb3231fe37fbcb9f8821620c52d7d8a4dad | exe | MarsStealer | |
| 2024-09-23 11:16:09 | 863c177542f93d6e42ba2dc7633cec75da9515c39ed13915f63e9361f5cf7a6b | exe | LummaStealer | |
| 2024-09-16 20:17:06 | 6b11a91599104b307955a4cde5942d89ed2aa29e833fa229e21368a73139186d | exe | Vidar | |
| 2024-09-11 07:20:07 | 6b11a91599104b307955a4cde5942d89ed2aa29e833fa229e21368a73139186d | exe | Vidar | |
| 2024-09-11 06:48:06 | d70176af4397fd3ce6b70a18a3b48ab445a7fa165cf0f758c5d02faa6387ea53 | exe | Vidar | |
| 2024-09-11 05:28:08 | ec9a1bede697caba74ff4666e0317cb3231fe37fbcb9f8821620c52d7d8a4dad | exe | MarsStealer | |
| 2024-09-11 05:27:06 | 05d5d2f7e1270d38d47870c349d22a7e02c9682ba123b1b5e8ae1aa4e3554087 | exe | Vidar |
ES