URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: larisantiara.com
Domain registrar:Shinjiru -
Domain registration date:2009-09-30 05:46:50 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-03-26 07:18:03 UTC
Total malware sites :21
Online malware sites :0 (0%)
Offline Malware sites :21 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-26 07:18:06 101.99.77.186Not listedAS45839 SHINJIRU-MY-AS-AP- MYyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-22 16:10:09http://larisantiara.com/content/kentttttt.ps1Offlineopendir powershell ps1 rat RemcosRAT ext abuse_ch
2025-03-26 07:22:06https://larisantiara.com/File/File/eng.txtOfflineopendir abuse_ch
2025-03-26 07:22:05https://larisantiara.com/File/File/syl.txtOfflineopendir abuse_ch
2025-03-26 07:22:05https://larisantiara.com/File/File/DAC.ps1Offlineopendir abuse_ch
2025-03-26 07:22:05https://larisantiara.com/File/File/ybin.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/ENG.ps1Offlineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/freak.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/big7.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/dac.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/guy.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/test.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/BIG77.ps1Offlineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/DDACC.ps1Offlineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/DDAC.ps1Offlineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/ssteph.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/syl.ps1Offlineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/MUK.txtOfflineopendir abuse_ch
2025-03-26 07:22:04https://larisantiara.com/File/File/MUK.ps1Offlineopendir abuse_ch
2025-03-26 07:19:07https://larisantiara.com/File/freak.txtOfflineAgentTesla ext ascii base64-loader Encoded opendir abuse_ch
2025-03-26 07:18:10https://larisantiara.com/File/DAC.txtOfflineAgentTesla ext ascii base64-loader Encoded opendir abuse_ch
2025-03-26 07:18:06https://larisantiara.com/File/DDAC.ps1OfflineAgentTesla ext ascii opendir powershell ps1 abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-22 16:10:09aea8b0d73e198c06aa3f916533376d1a66c4bcda353ed736ed3aae6f4c25ea14txtRemcosRAT
2025-03-26 07:19:073b107659e23b9c28725ee4827d5eb205eece8b9a5c90afbbb742a9832aaefaabtxt  
2025-03-26 07:18:09fe37d8823da9573b114c6c794849fde0a063abfddeba544835907e2afa317809txt AgentTesla
2025-03-26 07:18:06c4390777f9401bcbcec92376171f1c6ffaab28df84f314de54318c5376cbe20btxt