URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | leashcombine.com |
|---|---|
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2021-06-02 10:00:04 UTC |
| Total malware sites : | 8 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 8 (100%) |
| A record(s) observed : | 13 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2021-09-04 03:49:22 | 47.91.170.222 | Not listed | AS45102 ALIBABA-CN-NET | HK | no | |
| 2021-08-30 04:29:03 | 5.189.201.11 | for-migration.pav | Not listed | AS210756 EdgeCenterLLC | RU | no |
| 2021-08-23 03:09:14 | 5.181.27.27 | b.259565.xyz | Not listed | AS202422 GHOST | GB | no |
| 2021-08-22 08:14:13 | 45.8.126.70 | alphab.applopp.com | Not listed | AS214719 GBN | RU | no |
| 2021-08-01 17:30:28 | 146.185.239.5 | reserved.gbnhost.com | Not listed | AS63023 AS-GLOBALTELEHOST | ES | no |
| 2021-07-25 22:08:08 | 195.62.32.103 | Not listed | AS198584 PIO-Hosting | DE | no | |
| 2021-07-18 16:14:53 | 5.181.27.51 | vpn365-gb-02.com | Not listed | AS202422 GHOST | GB | no |
| 2021-07-11 14:01:40 | 103.150.30.179 | 179.30.150.103.in-addr.arpa | Not listed | AS132335 LEAPSWITCH-IN-AS-AP | IN | no |
| 2021-07-04 13:27:51 | 195.62.46.7 | Not listed | AS44592 SkyLink | DE | no | |
| 2021-06-27 13:05:13 | 92.38.171.38 | fghhjerwfg.com | Not listed | AS202422 GHOST | ES | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/pal/uNDyAciI4HH1... | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/yg/1WXmgkDYZGGom... | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/okb/document.exe | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/sam/FXBrhDMEiH6r... | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/adm/C51GBonCfOeO... | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/bob/p8YB5ygC4w0q... | Offline | AgentTesla | |
| 2021-06-02 10:01:06 | http://leashcombine.com/dmatel/effot/0DrMqGBx70... | Offline | AgentTesla | |
| 2021-06-02 10:00:06 | http://leashcombine.com/dmatel/jap/7cYoVozh4TGq... | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-06-02 10:01:06 | e3e8dc7df3c25fe3e8bbc80ea67ea740d2f4c02987a48826b0e8dd18161a5594 | exe | AgentTesla | |
| 2021-06-02 10:01:06 | da2c665eb8354455960a950eb4222e494e31fac2e5c03be0953cdb6232292dfd | exe | AgentTesla | |
| 2021-06-02 10:01:06 | 01da2dcbeaae73bc1e831a19cf6b1a8423c731a6da8648ffe3971e1e77de0758 | exe | AgentTesla | |
| 2021-06-02 10:01:06 | d53e73901e11b8b53e13f053e8d0fb23582b51c9fb0bab6374e7d68b686c4a84 | exe | AgentTesla | |
| 2021-06-02 10:01:06 | eceee7de24f317110e431f803e45c67c4356f5eb31ff996be8e1fef7989a5cca | exe | AgentTesla | |
| 2021-06-02 10:01:05 | 0cba20d5b04c149cb84b7dcc04c0e7a4f9ac7c8aef40016d6e09962f7b92bd6b | exe | AgentTesla | |
| 2021-06-02 10:01:05 | 85372d805986e3bb238b8fb8d985c549d3d51518c9d499c8b82a88d84cf3803a | exe | AgentTesla | |
| 2021-06-02 10:00:05 | 9dcb9f595fa8ecaa0ba4a8f677a4299f24c7e190546d856b5d7e9b6bce186998 | exe | AgentTesla |
HK
RU
GB
ES
DE
IN