URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ist-security.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-03-30 05:56:10 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 22:57:31 104.21.50.28Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 22:57:31 172.67.155.219Not listedAS13335 CLOUDFLARENETn/ayes
2021-03-30 05:56:17 150.60.158.61Not listedAS9597 MAINT-JPNIC- JPno
2021-07-25 09:46:52 52.25.92.0ec2-52-25-92-0.us-west-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-30 05:56:18https://ist-security.com/nz3wx4.rarOfflineDridex ext sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-04 00:27:3067951b6fdeb3686ae5063922c627ebd7bd2de6708ddb3f69d761e127203206f6dll Dridex
2021-03-30 15:32:0503bb64d1d0d91623bd8d83e769e97d39cf8175584dce06bc07936a8050ee4e41dllDridex
2021-03-30 07:25:3456cd0bb2fb78736e872dbb88fd9cdd78435b13e15c9b0be2b6ca709df36e93b1dllDridex
2021-03-30 05:56:166ccbc34952f3895fb847368112f920a4bdbc3c1ecab0c0ca1ea0d66da26ae0b1dllDridex