URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ji.ghwiwwff.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-04-02 07:53:10 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-05-15 08:38:29 103.100.211.218Not listedAS142403 YISUCLOUDLTD-HK- HKno
2023-04-02 07:53:24 104.21.87.159Not listedAS13335 CLOUDFLARENETn/ano
2023-04-02 07:53:18 172.67.144.158Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-04-02 07:53:24http://ji.ghwiwwff.com/m/oskg25Offlineexe fabookie abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-05-05 16:10:43a790b1752ac4a38d605b098c1d4d50aa8aeaf7a81aff8a48a57c42599c3e6790exe Fabookie
2023-05-04 18:37:309d4727c8d6ee3f645f9a77c512b84b0742d7502a15aeffcdd15366e6cb488c1fexeFabookie
2023-05-01 15:46:24c3e4b936392928fd4e1190f3ce396efd4495f1132f8aad00aab1d2dceed6bda6exeFabookie
2023-04-27 17:55:372f463640ede2ba652be4fbadf180af9b992917a4100e702c518405ac9ebe3aa6exeFabookie
2023-04-26 15:33:02f50a1f6a4a18f16169d39eae603f6300def0c4c8a8f6ad8807686f243e836314exeFabookie
2023-04-24 12:02:0397f12b24e5ae9141902e74706e7b1715a40e172bfd1eafab7271fb584b3b9796exeFabookie
2023-04-20 10:06:5300be39766b1a091a3f59c367143d21d511991a465c8eb0a39c907d4cd398c90aexeFabookie
2023-04-19 07:42:3694b3090468a91d8b931539c75565b8dc879bea77a1e1c106ae822d0526e6e636exeFabookie
2023-04-18 08:58:0281c46102daba9dec4485a7c9c7a198be3d2fc1c7b3a74edc9aad6474937b2499exe Fabookie
2023-04-17 04:17:12ea09c280645956baff7e4cdc2bfa9753104b9025ec81d6853fca43f8c2fcb732exeFabookie
2023-04-15 03:46:34f73ae637e2fabc59414bde71d114a8c941e8d8e73f0ba1bd956c07e5c5cf67dcexeFabookie
2023-04-12 13:47:51870a9633c0d413b49a3de2e9984c932a02fe7da019604707875a7e5f7d38124bexeFabookie
2023-04-11 15:22:190d68e80b05103406428c1d530d720966eef4a40f458c2ca315a0d449d7dd67a5exeFabookie
2023-04-10 13:16:1262ce1a784681de19ce663e50dafdbaadf1bef034127227950c47201523112042exeFabookie
2023-04-09 02:58:173c2eeb6f7925b176c3037df99473584b1621929b79a75573cfe335ff87c30e63exeFabookie
2023-04-08 05:01:38a52b15ce94bb5927e9dd482ae80661d3912603b5b93055599141cc28d5764cd9exe Fabookie
2023-04-06 08:07:101f9d101b831275091f28ff87eb66f5a76f8fc724d593704582a8ba541b0b3831exeFabookie
2023-04-04 16:27:364ec2e908cb0ec7053e456e6f1c1223a24979f7c0628798ffe22d8c8c575031f9exeFabookie
2023-04-03 05:34:421971e9d310869179bc49eac2515e440b278c6eaff37508d64054606c73ae1888exeFabookie
2023-04-02 07:53:12b4ea2b4b198552bd5507a504480d1efe41343c84c317de4ed44f571f608c8d47exeFabookie