URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lupasgroup.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-04-29 13:59:03 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-14 13:10:38 99.81.40.78ec2-99-81-40-78.eu-west-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- IEno
2021-04-29 13:59:04 179.43.183.46cphost21.qhoster.netNot listedAS51852 PLI-AS- CHno
2022-04-14 12:48:08 107.161.23.204parking.namesilo.comNot listedAS3842 RAMNODE- USno
2022-04-14 12:48:08 192.161.187.200unassigned.quadranet.comNot listedAS36352 AS-COLOCROSSING- USno
2022-04-14 12:48:08 209.141.38.71parking.namesilo.comNot listedAS53667 PONYNET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-08-05 17:50:18http://lupasgroup.com/Files/DBti7kFcOLHaK2z.exeOfflineexe opendir RedLineStealer ext abuse_ch
2021-08-05 17:50:18http://lupasgroup.com/Files/lLwIMX6OKZZo7VL.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-08-05 17:50:18http://lupasgroup.com/Files/5KNTQd5xFuY7hcE.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-05 17:50:18http://lupasgroup.com/Files/hWUsDVx5V2Kte0B.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-05 17:50:17http://lupasgroup.com/Files/77KpMaGlUit8zQl.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-05 17:50:14http://lupasgroup.com/Files/pscueWLrAI893Mm.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-05 17:50:13http://lupasgroup.com/Files/BuXTaVVWA5WdvtU.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-05 17:50:11http://lupasgroup.com/Files/h0AuDqUVLDrtpzq.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-05 17:50:10http://lupasgroup.com/Files/EgVhr9cVP2SFBEU.exeOfflineexe opendir RedLineStealer ext abuse_ch
2021-08-05 17:50:10http://lupasgroup.com/Files/Hlt9VTppbZE9UGs.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-05 17:50:10http://lupasgroup.com/Files/benu.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-05 17:50:10http://lupasgroup.com/Files/6Dy0Bg4B9kkMsak.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-05 17:50:10http://lupasgroup.com/Files/KVxnEZMWrmek1i6.exeOfflineexe opendir RedLineStealer ext abuse_ch
2021-07-15 06:05:04http://lupasgroup.com/Files/1Ptfo0FZUMT7hlK.exeOffline32 exe Formbook ext zbetcheckin
2021-07-13 18:57:03http://lupasgroup.com/Files/tukur.exeOfflineAgentTesla ext mattdep_
2021-07-13 18:20:06http://lupasgroup.com/P0weOPjsmVN5OCW.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-07-13 18:20:05http://lupasgroup.com/PfmlSN1LDSeCWfK.exeOfflineexe opendir abuse_ch
2021-07-12 09:21:04http://lupasgroup.com/Files/6th%20july.exeOfflineexe Formbook ext opendir abuse_ch
2021-07-12 09:21:04http://lupasgroup.com/Files/EMU.exeOfflineexe Formbook ext opendir abuse_ch
2021-07-12 09:21:04http://lupasgroup.com/Files/promise.exeOfflineexe Formbook ext opendir abuse_ch
2021-04-29 13:59:04http://lupasgroup.com/Files/s68r0hZ49vns9tk.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-04-29 13:59:04http://lupasgroup.com/Files/8BmVIdYzvSw7AD3.exeOfflineAgentTesla ext exe opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-05 17:50:18bc19e3e01dca70098a0d215f9ca4f7779ef62a76d2a4bfefe164dfd542035b0eexeRedLineStealer
2021-08-05 17:50:1811ec5629d8faba1d833f479be2741e05dbf9cf4e391a651afef4ed3b4f9b8cc8exeSnakeKeylogger
2021-08-05 17:50:1804e127c5bdf94f075639d7f44badd25223f3ebeede44258367413d8463505020exeFormbook
2021-08-05 17:50:1839f7d2aa6bd4b9aa4854434d59309e3fb16bf91b6b204bfbaa1fc0ad6d452f8eexeFormbook
2021-08-05 17:50:17b7259e9f3050809248c04326cc3af49d4eed3a0bd19c0905b32993a9c219bd3aexeFormbook
2021-08-05 17:50:1422f8bd6d14f40adb264992b23b49be37feeefeb00ff0702bfea5662b401ff8d6exeFormbook
2021-08-05 17:50:1328e9c4ad5816632edc837be54ccb120cbb6206e888b6671bc3ab935f1684e203exeAgentTesla
2021-08-05 17:50:1008da3e0469aeef33e9297ba4e98c67717fdff972a31782ccf539da0bf026bfb0exeRedLineStealer
2021-08-05 17:50:10a46daf608f092b3dfeccd1bd6f9709cf1b6f60dcc0ac5040b7b8321ac00f22cfexeAgentTesla
2021-08-05 17:50:104ac2dcd5ce04c588c08e4cd0350559bc8d5f7ff5c8302721619b74b39f61c786exeFormbook
2021-08-05 17:50:10a8a459f4d2976c7aca51862d982dd146eaee35f19d6e434d7224cbfdad6665cdexeAgentTesla
2021-08-05 17:50:10d4ac7a72eeea3ab4a778123b1ee1b804181a7d24b0e380f2874e68937de34cd6exeAgentTesla
2021-08-05 17:50:0903ca3c211536cd312b4e46531314c5ad021171026441e99f1d951b9ee8e29e46exeRedLineStealer
2021-08-02 10:04:1233cebe555952129003f55b9244a41296b081e23257be982732861aa8803775d1exeAgentTesla
2021-07-15 06:05:04fefa01b761aa8ab9d5a79db0bc41cd8eaee972248cf52e4d5c2629998e9bc6e2exeFormbook
2021-07-13 18:57:03fd39d881152cedb292077cc3bb13f87000b2b3bafd3275165385887350bd9fdcexeAgentTesla
2021-07-13 18:20:06002d56a69567db513519d5b528da88133425214a569e6f758dd20ac7492374fbexeAgentTesla
2021-07-12 09:21:0417d143d76b7279d4a2aba0ec3c614714384bbc57f7b5c1018a76ae7b60da7049exeFormbook
2021-07-12 09:21:04a09ad5ee3ef9214717004d7e8c2761a0a2f010e74755f4c99ab4be8d592794ccexeFormbook
2021-07-12 09:21:0447c700a9a4cc5589c3acd273c4536952c5c0db7ad1f94408b4e6097d48fdb581exeFormbook
2021-04-29 13:59:0448899f3f038a01c3dcf2d263e0232ccc3c44fff9635165f894d7da232e625bf1exeAgentTesla
2021-04-29 13:59:04a1b75ed16d694a8f21c0b88484257811fec12cabd0b2ccdaebb4f4c1754f32aaexeAgentTesla