URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: husktools.duckdns.org
Domain registrar:Gandi -
Domain registration date:2013-04-12 19:58:56 UTC
Abuse complaint sent?: Yes (2024-11-05 13:20:02 UTC to support{at}duckdns[dot]org)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-11-05 13:19:11 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-11-14 15:42:30 87.121.86.126Not listedAS209693 OC-NETWORK- EEno
2024-11-21 02:55:03 185.195.19.214mluei-214.bametar.comNot listedAS9009 M247- ROno
2024-11-21 11:40:05 185.195.19.213mluei-213.bametar.comNot listedAS9009 M247- ROno
2024-11-21 04:37:38 185.195.19.212mluei-212.bametar.comNot listedAS9009 M247- ROno
2024-11-14 19:06:02 185.195.19.194mluei-194.bametar.comNot listedAS9009 M247- ROno
2024-11-19 00:39:58 185.195.19.195mluei-195.bametar.comNot listedAS9009 M247- ROno
2024-11-14 18:21:37 185.195.19.196mluei-196.bametar.comNot listedAS9009 M247- ROno
2024-11-15 10:02:31 45.89.175.86Not listedAS9009 M247- ROno
2024-11-05 13:19:25 31.13.224.189Not listedAS151612 HOSTPERL-AS-AP- NZno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-11-08 19:43:06http://husktools.duckdns.org/joined.exeOffline32 exe xworm zbetcheckin
2024-11-08 18:10:10http://husktools.duckdns.org/worm.exeOfflineAsyncRAT ext Bitsight
2024-11-07 04:47:07http://husktools.duckdns.org/lum.exeOffline32 exe LummaStealer zbetcheckin
2024-11-05 13:19:25http://husktools.duckdns.org/xwo.exeOfflinexworm Bitsight

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-11-08 19:43:067245244c75276269f56cce5f81194681a881d4746a7abec6807f28a19b04ba66exeXWorm
2024-11-08 18:10:10a1c97fe85170fd6acd766d965f1931e32692ffa92db222492fd24b4421b126c9exeAsyncRAT
2024-11-07 04:47:0677f6caa506303dbdcf644380adf5cb01b122f6f5efa3a54d7492754075243e2bexeLummaStealer
2024-11-05 13:19:20a22f6db007744f7768782280e66832487b3b193ff20825203bb56210b7c4e923exeXWorm