URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lontorz.xyz
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-29 06:18:03 UTC
Total malware sites :13
Online malware sites :0 (0%)
Offline Malware sites :13 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-06-29 06:18:04 185.239.243.112ns1.20mb.nlNot listedAS212238 CDNEXT- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-06 20:23:04http://lontorz.xyz/mazx.exeOffline32 exe SnakeKeylogger ext zbetcheckin
2021-07-06 18:11:03http://lontorz.xyz/chekwaz.exeOffline32 exe SnakeKeylogger ext zbetcheckin
2021-07-06 15:45:04http://lontorz.xyz/bigheadx.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-07-02 19:28:05http://lontorz.xyz/ashleybinx.exeOffline32 exe Formbook ext zbetcheckin
2021-07-02 15:48:03http://lontorz.xyz/ashleybuildx.exeOffline32 exe Loki ext zbetcheckin
2021-07-02 07:43:07http://lontorz.xyz/wealthx.exeOfflineAgentTesla ext exe abuse_ch
2021-06-30 17:46:03http://lontorz.xyz/ujunkwerex.exeOfflineexe NanoCore ext rat abuse_ch
2021-06-30 17:46:03http://lontorz.xyz/catx.exeOfflineexe NanoCore ext rat abuse_ch
2021-06-30 17:46:03http://lontorz.xyz/un.exeOfflineexe Formbook ext abuse_ch
2021-06-29 19:39:04http://lontorz.xyz/aguerox.exeOfflineAgentTesla ext exe abuse_ch
2021-06-29 12:57:04http://lontorz.xyz/bluex.exeOfflineGuLoader ext Loki ext James_inthe_box
2021-06-29 06:21:05http://lontorz.xyz/bobbyx.exeOfflineAgentTesla ext exe abuse_ch
2021-06-29 06:18:04http://lontorz.xyz/kdotx.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-07 08:29:141e7c33164f07dc380f9866ac4941b7fcb01b7099342e47254af509710049f5d2exeNanoCore
2021-07-07 01:59:0705d1cd8ecd12ffc2c26529d25bcb0e0fe82a26e88297abfffb05b66637f24fd1exeSnakeKeylogger
2021-07-07 01:43:56eb0ec020c264ad8ed9407e5f55e4b45c57336603eef31bae5a6c5f55b7c39be1exe SnakeKeylogger
2021-07-06 20:23:04d9ed8af079bdd7fef1daa51696fe0172d5170fd4ee668ed2f252cbe65a2ab488exeSnakeKeylogger
2021-07-06 18:11:030625021c787b2f711eb6fadc44856a9f001037bcb29686b910c557316bcbf212exeSnakeKeylogger
2021-07-06 15:45:0484a07c64cd318963d10bad4eead98e7f186f136d7e74725cabac4246b56e1712exeSnakeKeylogger
2021-07-05 08:21:08647e820900272cc662ccf0ae12baaf80f387b1c4f50c70ab8af390ddd88f235cexeNanoCore
2021-07-05 08:16:235c60d493bc913c9986a8b7007b138b7bc71b2989e3edd4a30bd3cd27ad64db72exeAgentTesla
2021-07-02 19:28:054d8eaf37de32a6ff36c965b6e616e2085e2d1bd46e75344ca1fea59178c19f15exeFormbook
2021-07-02 15:48:0311a5e063d4c121371a3de04d5b32352cc86d65f51b42b5437c1e5f7e17498fbfexeLoki
2021-07-02 07:43:07915c4f38aa51645084c1745bae8495d8c571f2b813bba72ba0b28f98bb94ad5fexeAgentTesla
2021-07-01 22:55:2143ee89c14274dbfb7cc6c39fffcc59ffdc08c5581450928c7420570bd74bffbeexeNanoCore
2021-07-01 11:02:368bea87933992abf0ab4498cdba996141e3764889d31ccb50c966619f1dbbaaafexeNanoCore
2021-06-30 17:46:031feda728feb0187e19e099ddfcb542c608b3ec67149592520c1515bc6d3ada03exeNanoCore
2021-06-30 17:46:039821a5def0375e6e5c1a5cdf9385077108ea08d92ba8ec23aca91e15fb2fe074exeNanoCore
2021-06-30 17:46:03005cdcb32ac1705413e9dd2049e791a6eb2fb22274ce4fece226f9010b6cff02exeFormbook
2021-06-29 19:39:0450050452f22edd51ccd484e785ceabed4990fe67806c1c42fcd7cbe1ee40e779exeAgentTesla
2021-06-29 12:57:030aaaf9c1e77b1a34004d45cac0b780ac1f67797244be20c355056251a5b478a1exeLoki
2021-06-29 09:22:029e614b7116a337119dc6f8c32722859fc862f485bc0169c66ad958b63744ceafexeAgentTesla
2021-06-29 06:21:058479820a0aa9a814e532b5b2f6e7e172f3d3dd9f651375b695c37ca75c84d946exeAgentTesla
2021-06-29 06:18:04a940dd76428496c9d30336bab7130c072333f4482e2aadc30952d3e35a86400cexeAgentTesla