URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: joejoestdyhegrenfxcj.dns.army
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-03-11 09:31:03 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-11 09:31:07 103.141.138.120Not listedAS135905 VNPT-AS-VN- VNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-11 09:31:07http://joejoestdyhegrenfxcj.dns.army/documenjt/...Offlineexe Loki ext gorimpthon

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-03-12 07:52:12e9e6188efc11359d75e75bf67c28b7579ddcb507ad10afea8c721d4e8bd5e470exeLoki
2021-03-12 04:54:4622974bdf9bc9bb3d9aa35a21377f7d8d178ba35d65fca200cf2b627b0ee0e2d9exeLoki
2021-03-12 02:44:45319859aa3af3d46e72837db20ea4f62787520ea70941cc5a0c6fc4fe81242ad6exe Loki
2021-03-11 21:31:15b7bb35d04c43970a32711eb06080774b5b1d56260fe28b8f7c65206372943e7cexeLoki
2021-03-11 09:31:07483d6ae983874e7a225f99747d490194256ace1b9ca6e0457dd871c70b4f83d1exeLoki