URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host ghancommercialbank.com.

Database Entry


Host:ghancommercialbank.com
Spamhaus DBL:Spammer domain
SURBL:Not listed
Firstseen:2018-11-24 09:30:02 UTC

IP addresses


The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-11-24 09:30:0380.87.203.19mhost18.ispserver.comNot listedAS29182 ISPSYSTEM-AS- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2019-02-25 05:23:29https://ghancommercialbank.com/js/good.exeOfflineexe njRAT payload Clean@shotgunner101
2019-02-25 05:23:23https://ghancommercialbank.com/ex/doc.exeOfflineexe payload Clean@shotgunner101
2019-02-25 05:23:16https://ghancommercialbank.com/VJ/frclient.jsOfflineexe payload Clean@shotgunner101
2019-02-25 05:23:06https://ghancommercialbank.com/NJ/server.exeOfflineexe NanoCore payload Clean@shotgunner101
2019-01-06 20:44:03http://ghancommercialbank.com/ex/doc.exeOfflineexe Clean@zbetcheckin
2019-01-06 20:40:13http://ghancommercialbank.com/NJ/server.exeOfflineexe NanoCore Clean@zbetcheckin
2019-01-06 20:40:04http://ghancommercialbank.com/js/good.exeOfflineexe njRAT Clean@zbetcheckin
2018-11-24 09:32:02http://ghancommercialbank.com/psi/frclient.jsOfflinejs opendir Clean@cocaman
2018-11-24 09:30:03http://ghancommercialbank.com/msn/newclient.exeOfflineexe njRAT opendir Clean@cocaman