URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: fxqy.my.to
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-25 14:59:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-07-06 17:21:47 37.0.11.114Not listedAS3758 SINGNET- SGno
2021-06-25 14:59:05 2.56.59.221Not listedAS3758 SINGNET- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-06 19:12:04http://fxqy.my.to/EXCEL.exeOffline32 AveMariaRAT ext exe RemcosRAT ext SnakeKeylogger ext zbetcheckin
2021-06-25 14:59:05http://fxqy.my.to/tasksmgr.exeOfflineAgentTesla ext AveMariaRAT ext NanoCore ext Neshta njRAT ext RemcosRAT ext Xpertrat Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-14 02:33:136be01e50e16e3b04ecc12d5c95265fedd7ed3e2c8b5125aa1eaef1d2ded5aef9exeNanoCore
2021-07-14 02:31:0420abe25c4f02f73cdda3e8e74187202fbdbf5fa2fd7fe92b2d1ab328b66c1950exeAveMariaRAT
2021-07-13 17:42:25bfd78e2e17970e07df2c1a566480c5e1cc7bdc64176915b62fda6f5ee2a1f70fexeNanoCore
2021-07-13 11:50:29dd5107d7cc5b86ef5a650ea6e01b662066c34072859272fa886379e304e7df43exeRemcosRAT
2021-07-13 11:47:58d7f2fddb43eb63f9246f0a4535dfcca6da2817592455d7eceaacde666cf1aaaeexeXpertRAT
2021-07-13 08:39:3259d18f1afca7fa22d68455d412c29949993c21edfb3658091bdad62093e0f818exeXpertRAT
2021-07-13 07:54:3704cde0c2284cc4dc8f8a5aeadafca6819ab9d11dfb76fb7f3a2fbbf91d3c0e5dexeAveMariaRAT
2021-07-13 06:52:4737a9969f1c0394c3899ffcd2fcebf9c9393bc712da4c80d4cdb2b19adec5334fexeRemcosRAT
2021-07-13 06:49:09538b973f12e7eb9390b9b64cb36818b73b139bee73af7d5c7b8c5d72a0dc037aexeAveMariaRAT
2021-07-12 11:05:36846eaabb020cae8d55f447aff654108fb327543653b1412b07480ef59927cffdexeNanoCore
2021-07-12 03:52:018c366ee263db756db2648d00eb615b16fc8b92262f8bdf7d3269267eb1382cb0exeSnakeKeylogger
2021-07-11 14:56:41394b84714c723fe917d65356700c36483a29610251eb06b93fb4a2b0922a68a4exeAveMariaRAT
2021-07-11 03:41:012c2ce93844f1742c83a36255e95c4eaa3ce0fb3162891968b22ee3dd46abee2aexeSnakeKeylogger
2021-07-10 11:12:06c877097a2a3852b34c2ee4b0c7b2f5c7a3dc5313570e0680e04adea7e44201efexeAveMariaRAT
2021-07-09 17:45:094802b87ba7e4f7c1815d0c027aab96c0fcd74099ea8fdd236a9909e0ca00faf6exeSnakeKeylogger
2021-07-09 02:54:44f99002091475b0c5f423e2d9efe182de66019616c5fda6205efc3d9bd2f5ff45exeSnakeKeylogger
2021-07-08 07:26:09d5bf73c697fe079c68e107fa41cc97a328c6190507a8514a26376ef554659d9dexeSnakeKeylogger
2021-07-06 19:12:0471d43dd5594e4d74bc9c4e79f13089f1f8938831f8155c49025d634cb9ab2423exeSnakeKeylogger
2021-07-06 17:36:463ba615a4d99b560c58bed9e63c8ecd2c20dbc71560ec1fe51ca2b78a6b8309e6exeNeshta
2021-07-01 02:45:30cc29d221864706dcc32aff35a4a7a246c310aa7fd8fd4cb254ad36fb415fe3ffexeNeshta
2021-06-29 14:53:46b79cfa964a72547debcda5eb2c09c2c4c04b03a963b68dd6abc11423cd2262efexenjrat
2021-06-28 07:03:052b1e0b1b320aa81b41cf142297135183f00ad695517f12d3f715fd58eaa6a9c2exenjrat
2021-06-25 14:59:0559c0a91faf884e242be0d2384d94eba2536a8f155ae568355eed225f2543176eexenjrat