URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: grisando.info
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-23 16:36:05 UTC
Total malware sites :1
A record(s) observed :17

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-06-20 22:06:43 52.15.56.78ec2-52-15-56-78.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-20 22:06:43 3.21.0.145ec2-3-21-0-145.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-20 22:06:43 3.134.143.128ec2-3-134-143-128.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-11 14:44:11 18.190.101.130ec2-18-190-101-130.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-10 08:03:07 3.136.195.119ec2-3-136-195-119.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-10 08:03:07 3.133.215.23ec2-3-133-215-23.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-06-23 16:36:09 172.67.164.129Not listedAS13335 CLOUDFLARENETn/ano
2021-06-23 16:36:08 104.21.15.216Not listedAS13335 CLOUDFLARENETn/ano
2022-05-05 21:03:50 188.114.97.6Not listedAS13335 CLOUDFLARENETn/ano
2022-05-05 21:03:50 188.114.96.6Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-23 16:36:09http://grisando.info/app.exeOfflineexe glupteba ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-06-23 20:47:26e718a8778287f4e364f7351a0c40b8342f98da515601921d1844b3efa5ced16eexeGlupteba
2021-06-23 19:03:00cc989c2ce0009387572c60ac3e0c4554162fdd6713520e9aaf1bf20e039e154dexe Glupteba
2021-06-23 17:35:33b40d3f5493f03dd8fa6efc0d3f02c7f67d3ca76daa45dbec75887cb6eb013461exeGlupteba
2021-06-23 16:36:083ed60a60c3aeb99f383ef97de1581827c535d082cf9f33c5fe6ef572fc186a94exeGlupteba