URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ghghfgc.b-cdn.net
Domain registrar:Name.com -
Domain registration date:2016-04-25 23:34:57 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-10-20 13:13:09 UTC
Total malware sites :1
A record(s) observed :33

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-30 07:02:54 185.59.220.198185-59-220-198.bunnyinfra.netNot listedAS60068 CDN77- DEyes
2023-01-07 18:18:57 169.150.247.39169-150-247-39.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-12-15 13:08:20 138.199.37.232138-199-37-232.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-11-26 18:36:41 89.187.169.4789-187-169-47.bunnyinfra.netNot listedAS60068 CDN77- DEno
2023-01-22 02:04:19 169.150.247.34unn-169-150-247-34.datapacket.comNot listedAS60068 CDN77- DEno
2022-11-20 13:16:13 138.199.37.230138-199-37-230.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-12-04 23:10:25 138.199.37.227138-199-37-227.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-11-28 02:47:40 138.199.36.8138-199-36-8.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-11-21 21:09:09 138.199.37.231138-199-37-231.bunnyinfra.netNot listedAS60068 CDN77- DEno
2023-03-17 05:17:43 169.150.247.40unn-169-150-247-40.datapacket.comNot listedAS60068 CDN77- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-20 13:13:11http://ghghfgc.b-cdn.net/chromeUpduter.exeOfflineCoinMiner exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-20 13:13:11054174b77c43d2b1a97a1238282818dc2792535ec0e3b94102c58d9d9ffeba15exeCoinMiner