URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: kiffdd.eu
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-03-20 14:54:09 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-20 14:55:12 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2023-03-20 14:55:12 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2023-03-20 18:15:24 104.21.72.41Not listedAS13335 CLOUDFLARENETn/ano
2023-03-20 18:15:29 172.67.174.204Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-20 14:55:12https://kiffdd.eu/gallery/photo_004.exeOfflineAmadey dropped-by-PrivateLoader RedLine ext RedLineStealer ext andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-21 18:28:4303074eab66e0df98879d051c0ab0e4d7d51f805ec4e276f3849038086a0d3b38exe Amadey
2023-03-21 16:05:46d668c1e7315bf1f3b3130ef277cdbfa2df4133458b703597b166db23ca3e2df7exe RedLineStealer
2023-03-21 14:19:19f7e684a999f1afb9fe365a9166b61f36742c40a7fc932a1d3072141ad162c1a8exe RedLineStealer
2023-03-21 13:17:45e8051e7adf9c0a30eee4b2c10a70e3631bd8d423ecff8a25cff923012ad548e8exe RedLineStealer
2023-03-21 11:19:01dd2e73a81f2770b3d5b8e46d26f17b1436fd974ecc5bb3bbab79190fb9216348exe RedLineStealer
2023-03-21 10:39:25ef7a11c29ec0850317f03ef5e13953f6c99e4c42c10a0fc066e305ef30c5eaacexe RedLineStealer
2023-03-21 08:01:34dad4f3a7f3f5449cf8472713c9c1b3f0539bcb34280f2e71156891087518e80bexe RedLineStealer
2023-03-21 06:28:4647fd89d46ed1b1d7cac0e63703aa3d2e37d073b02f1196820f398013fa76cde6exeRedLineStealer
2023-03-21 05:18:403b1f12a3fdf1e67b9f993af22730c3acf71b22e9fb4f04146449307057a8b02cexe RedLineStealer
2023-03-21 03:01:398606b0f3527f7b774ac1ffe598ee338ffa6247a639baaf3a9c86f95552973f8bexe Amadey
2023-03-21 02:16:327be9aa7eaf74233ec29c6a4ce26f8303fc6dd8db69d7f5e3a1ec5d4099293a1cexe RedLineStealer
2023-03-20 23:02:242558cf38481549c9fdd11d2b3fde4b0168c8d7fb7726dd8f588e60e22794ac6bexe Amadey
2023-03-20 22:19:20a3d578e74702ef75d093a8889312c107c4d13dda49e2b5a3691889fbe2974b37exe RedLineStealer
2023-03-20 21:27:17dc48d4481ecd39df258074f0929d6a0c86b0ce6574a10bb0334a576eca51bc08exe RedLineStealer
2023-03-20 19:03:52224cee378b67674d5ea79fb914623b65ff311329e3e0c50144203022fd31c40fexe RedLineStealer
2023-03-20 18:15:174dfd5e024141a89e370b51fee30b3433c565aed0612cf2390fb6952a106d960eexe RedLineStealer
2023-03-20 17:15:392986b0dcfe8ca62d0ec4a98db00e0553699ff5302e8c7df0a82916bfc4286b6dexe RedLineStealer
2023-03-20 14:55:12ade3c4253697855fa9052ac13e5dc96a4a830b9bf85790fa11cafa2770b6eb9bexe RedLineStealer