URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: foxthreatnigger.botnetrealsexo.com
Domain registrar:Tucows -
Domain registration date:2024-05-23 17:15:55 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-08-14 16:50:06 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-27 23:11:56 52.223.13.41a74e89cf4458da039.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2024-08-15 20:05:02 193.124.33.3ib.systemsNot listedAS41745 FORTIS-AS- RUno
2024-08-15 20:05:00 45.65.9.79forkcontato.example.comNot listedAS202422 GHOST- USno
2024-08-15 20:04:57 45.89.63.160Not listedAS41745 FORTIS-AS- GBno
2024-08-15 20:04:59 80.91.223.72tube-hosting.comSBL694296AS49581 TUBE-HOSTING- DEno
2024-08-14 21:34:49 95.214.27.201Not listedAS20911 NETSURF-AS-BG- BGno
2024-08-14 16:50:07 95.214.27.157Not listedAS20911 NETSURF-AS-BG- BGno

Malware URLs


The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-14 20:03:07a6c42b64d224e03b72c55776d7cb787f75b930bd81ae34ce4a0177682d30bed6elf  
2024-08-14 20:02:24023c581fb54ef976de431263fa4a9a24b00edfc69287c5548f1c6826f68f8b46elf  
2024-08-14 20:00:344469294a9a8d8261e14d53ad739c0738bcd83cd257ce31abd599378c3ffef907elf  
2024-08-14 19:57:30c4eca8170f29f1586d15a000a8166fb01e4219fb8b09d9f13c1edb3810e2d5beelf  
2024-08-14 19:49:1595d03ecc9213038b069d414238d769efaddc6551ee9015cf8f760a480f827a14elf  
2024-08-14 19:43:577d95b05daaebbc0747168ae9a1fdb106ef362b9b263209bb584d883633222dd9elf  
2024-08-14 18:55:1000f9c93bd0ea648705dafdbb4ed7424aef9ec08b0f6bb6b542dd4da07ac11928elf  
2024-08-14 18:46:44bd1bf8c3fc051b2116bb551e68e029b305b0acf98e41ab9b8e4dff27f1221a4aelf  
2024-08-14 18:41:513cb8d5bc74c7e8d2f1ae97876b5683201a587834bad7b64e63ab451e4d6478ffelf  
2024-08-14 18:22:1054fcbe580b68fd863520efc9bf74fd009e484798f4dda351a2373c1f5c1cc8d8elf  
2024-08-14 18:18:38de7110c27d7d37d7fc9768f27ab945673703ed4ad8814a6fafb5f2c81c9680c6elf  
2024-08-14 16:51:07998ff840c197c162cb3e7f4dc853c0e5bb1cb46a4e0c8fc3e35c03729c166225elf  
2024-08-14 16:51:07629569c201db8921c3197480dd320e56fcdcd02c28083c241fd134a6c7637f1aelfMirai
2024-08-14 16:51:0679020c43a101f34f5f8aecf10874de058363b4bb2ced568dee4aeb3f2dee25f6elf  
2024-08-14 16:51:06cf60e8fd0b216a00a97ef2447e548a03549763b7767d515b7dc06bcfe05daaadelfMirai
2024-08-14 16:51:06c3a6337b23fd79eb424fcaed0e581c8519bf402de4f930cc4417a45820d7b430elf  
2024-08-14 16:51:05ab75fb65c83420f3bf842e5fa48eee7a8b19a94c32819d550c7b6de27f6e37c1elf  
2024-08-14 16:51:053b75abdd3c1eca277fee5bb209b08d7a82d906e2df73f63e8ac5011205e1ad1eelf  
2024-08-14 16:51:0533a83142e46b77c2059cdea0933d64f4d7f4c1249f3ebde4c38a4d60f21085c8elf  
2024-08-14 16:51:059ad1537074e2a17bd029414462b72a84562534068d5cdce59d3a860a0a667a30elf  
2024-08-14 16:51:05b7f022581e121991baca83e8df206f70ee4ea574f332db3e0a8890c69be91524elf  
2024-08-14 16:50:075cf6d13ff7a945039871894bd7d0af45dd142250e5f6d295512d29fc5c965902elfGafgyt