URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: kjarz.com
Domain registrar:Dynadot -
Domain registration date:2025-11-24 11:56:46 UTC
Abuse complaint sent to registrar: Yes (2025-11-26 15:07:02 UTC to abuse{at}dynadot[dot]com)
Domain registry:VeriSign Global Registry Services -
Abuse complaint sent to registry: Yes (2025-11-26 15:07:02 UTC to info{at}verisign-grs[dot]com)
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-11-26 15:02:07 UTC
Total malware sites :4
Online malware sites :4 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2025-11-29 07:12:12 UTC
Oldest active malware site :2025-11-26 15:02:19 UTC (Age: 2 days, 22 hours, 46 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-26 15:02:19 88.214.50.121SBL680556AS216341 OPTIMA-AS- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-29 07:12:12https://kjarz.com/BMUAUFKZ.msiOnlineHijackLoader huntio opendir BlinkzSec
2025-11-29 07:12:09https://kjarz.com/MRXTOHRL.msiOnlineHijackLoader huntio opendir BlinkzSec
2025-11-29 07:12:07https://kjarz.com/uri.htmlOnlineClickFix huntio opendir BlinkzSec
2025-11-26 15:02:19https://kjarz.com/j.txtOnlineClickFix obfuscated threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-29 07:12:128986d305ceed84c8dbc430ae7caf31b645f22fe5c4c29bca869eaee9abc46585msiHijackLoader
2025-11-29 07:12:09ba8f2313b3398187c424d9abed5f735907d01ebc9a11077136d2919e369501d6msiHijackLoader
2025-11-29 07:12:07dbb8ee5c48e8d7d0d40efaf81654957fbda3da5af0e13300bf0be8108071f657html  
2025-11-26 15:02:19086d9294348d95feb9f740db515f9708d2ab76cfa15815b7c7f79122932900detxt