URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mail.rigid-group.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-12-08 17:56:03 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-12-10 14:40:07 85.187.128.33sg1-ts3.a2hosting.comNot listedAS55293 A2HOSTING- SGyes
2021-05-19 03:48:46 104.21.55.112Not listedAS13335 CLOUDFLARENETn/ano
2021-05-19 03:48:46 172.67.171.30Not listedAS13335 CLOUDFLARENETn/ano
2021-11-23 21:35:24 188.114.96.44Not listedAS13335 CLOUDFLARENETn/ano
2021-11-23 21:35:24 188.114.97.44Not listedAS13335 CLOUDFLARENETn/ano
2020-12-08 17:56:03 85.187.128.9sg1-ss7.a2hosting.comNot listedAS55293 A2HOSTING- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-02-17 21:46:16http://mail.rigid-group.com/k82dwrxan.zipOfflineDridex ext stoerchl
2021-02-04 15:11:16https://mail.rigid-group.com/jp/phpformbuilder/...OfflineCoinMiner.XMRig Dridex ext Cryptolaemus1
2021-02-04 15:11:12https://mail.rigid-group.com/jp/phpformbuilder/...OfflineDridex ext Cryptolaemus1
2021-01-27 20:24:13https://mail.rigid-group.com/jp/phpformbuilder/...OfflineDridex ext Cryptolaemus1
2021-01-12 11:54:03http://mail.rigid-group.com/singularity.phpOffline cocaman
2020-12-08 17:56:03http://mail.rigid-group.com/underestimate.phpOfflinedll Dridex ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-02-18 09:02:3808770b7ce4f415232f98b641ae609c593dcf6a0907d854fe2acbdbe01c5b6d2cdllDridex
2021-02-18 04:09:37582f062af319c7e2f23be49d321125334f497b9eebe9ac997bbd00d883020e68dllDridex
2021-02-17 21:46:163391f266ecea6f5fe101269bb944ab7a4d79be9f3d2da0823b839ca485ff984fdllDridex
2021-02-04 18:46:22455e442d7efbb5712011f183c27f0dfa61297c938de00d9e649240d7bb83a56ddll Dridex
2021-02-04 18:34:02d52402cca93f6bfb7b8ef2351a931a3ed0efcb9cb628119753cd283ca960fe9cdll Dridex
2021-02-04 18:18:2343985241fc96c46dcbbe28227711db6c94bd211d833658fde705b820198ad11ddll Dridex
2021-02-04 18:04:2756b8a3cdbfa6d2f79e7e8e2b0860d8f5fb14578e871eeaa3bcd0fbc89853ce4edll Dridex
2021-02-04 16:58:39a28ecbd1cf35e41412a3464c7a04f985164bf052da0a3593f753df2a9f1d6f41dll CoinMiner.XMRig
2021-02-04 16:17:54695c8cf795799eedf8cf44f177708dfa50c412661fe6807fbd4a1a7f53dfcb1ddll Dridex
2021-02-04 16:10:08b60d9bf847c8343438cda1b9bf66cc2ffe3c364086eca57c99a65e1354e8d812dll Dridex
2021-02-04 15:55:57cafd19092a9264ea11a1aaaa9adfbd049205f62f2ba49c4a20a9935cf3f95802dll Dridex
2021-02-04 15:43:27cd7111d5ba2b9ae14f13b32d76d0531055f5bd930df6e3fd6ec933d5de3eab01dll Dridex
2021-02-04 15:29:04f5d28c8747f474f442f3bcd1bbc7c49e582f0775d8855739a0426bff18cccd4ddll Dridex
2021-02-04 15:11:16f5c7895e561624fec517b6230d0817bdc62d5781cda22b10ca646e6407c0db49dll Dridex
2021-01-28 00:22:26e16180f593556be1988db6fa8f6dae3e6668deceb67256894152123740088327dll Dridex
2021-01-27 23:30:07b22e6554ae819c5caff73528cf8e94dbae6881a9eb73201fd2cb842740caba6fdll Dridex
2021-01-27 23:20:13489cd518e8dddf02234e2e89bbc32f93cf6264cd6b7fa538c5485eeca5c4e97bdll Dridex
2021-01-27 22:31:5901afc140385f2fbcbed59bf534c71da2b2e45b21c87e7f7076918d9949efc4d1dll Dridex
2021-01-27 22:03:477be227715b752c196963b191fed3d0c091b1a3bda62f076517299a51e8f83803dll Dridex
2021-01-27 21:49:5383dc80c76b4c64abcf0862b8638271a17f6fb24a5e5c70fb3164711e6d3ab178dll Dridex
2021-01-27 21:40:467ceffa52a4d201ed472f3a2aead2efb283fc24ac5fab05246626cde7f7e07067dll Dridex
2021-01-27 21:21:01490c387e6fef9481711483e80164af60122dc07cce185f66f4c2800006f2c93ddll Dridex
2021-01-27 21:00:1102340826cb84fe3c40f70f8ecc6280a6bca9b23a6debde3bc2e616d7cdeb2fefdll Dridex
2021-01-27 20:53:5271a9148ffc10b2200d21e6f648ea2c51e59d885ae44c126d7a4b1a131404ad28dll Dridex
2021-01-27 20:34:17a003bf77fb05d2e7704934911bac9e781f1cc1e9d6a06b9258c4e96ce6557b44dll Dridex
2021-01-27 20:24:139d1d425abf972664469553a89f6852fa088af98a0a65aa6cf1933e2eeb3be3c9dll Dridex