URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mandalaagrifresh.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-12-23 17:44:03 UTC
Total malware sites :1
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-29 13:08:40 103.138.189.58s11643.sgp1.stableserver.netNot listedAS204800 WHG-SGP- SGyes
2025-04-27 20:09:23 192.250.235.26s1304.sgp1.mysecurecloudhost.comNot listedAS204800 WHG-SGP- GBno
2022-12-23 17:44:10 207.148.117.199s482.sgp9.mysecurecloudhost.comNot listedAS20473 AS-VULTR- SGno
2023-06-16 19:08:12 199.59.243.223Not listedAS16509 AMAZON-02- USno
2023-01-10 03:58:11 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2023-01-10 03:58:11 188.114.97.3SBL691350AS13335 CLOUDFLARENETn/ano
2023-04-27 13:12:24 104.21.70.91Not listedAS13335 CLOUDFLARENETn/ano
2023-04-27 13:12:30 172.67.222.45Not listedAS13335 CLOUDFLARENETn/ano
2023-01-13 12:35:57 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2023-01-13 12:35:57 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-23 17:44:10http://mandalaagrifresh.com/blog/Cancellation_7...Offline10900 geofenced iso obama233 Qakbot ext qbot ext Quakbot ext USA zip Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-31 02:23:05c3cef0d64c1f62713be5b27d586af79e9bb65d8ba78117c951c758d421aa1038html 
2025-09-27 16:58:4100be7f643a12ac2221c9ba8df4fb34b3701c336fa830d24fe906c55364ef7b35html 
2022-12-24 22:15:2708a44110fca717e9a82fa3a2cb728776db4dfe6410d504088ac68f7e799e90f3zip  
2022-12-24 20:25:34743be7facfbdd33d5615f4d9e2f9941a73a6cf11de0265423ea0c0da30cd6245zip  
2022-12-24 19:05:21180b0bb5babdf17fbc5ca775924bebdb9f75d14c03d2ec6ed86bc739779a6fbbzip  
2022-12-24 17:22:184abd6969c5db1c45c9382ded15acaad59a6587aae77f3f4b43265ae076c28f7dzip  
2022-12-24 15:29:42aca896ac6726a437e686f3ccb66368e7a5c2effc5825d8bc72ec5696d66fd501zip  
2022-12-24 14:07:41738a286e70b0f1a8d735db3b8b4c20aaabfbdeef1da15ea6b95da7f23f3f9dc9zip  
2022-12-24 11:58:30bfe3a87866003b8f0647e65c5bd22d54270c7010bd4d7e86c454d1e4006c45e9zip  
2022-12-24 10:27:282422beb9fc76b09cd8ba7ebbb9a39106f9a3dfd9d6ca1fbe733838ef9e55ed59zip  
2022-12-24 09:17:10ec893ff84ed1e33bad60e8ee2563d08cf77e65cbc4d387cef017f4074937dc26zip  
2022-12-24 08:16:47954115b497ad5b1074b0a841987781fc37c0e5d3619dfaa2a51fb2cd61c3e1adzip  
2022-12-24 08:09:58776bb7a422a5f667e7f46f94ac581509e4b89d7736d0ce333e53a14c9f4d3b78zip  
2022-12-24 06:16:57800d6b55f8591c60d01306b8c99488dcc6c2d11cfcb6dd720e59535ec1475635zip  
2022-12-24 04:29:33e3b213442a8b9278b39bbe14df46446fe2f94ba9dde0762be7f18983fddeea52zip  
2022-12-24 02:32:203417e7cc2ca2b35057d6ecc0daabef7c9457310e600443b4cbba5f0be0747a34zip  
2022-12-24 00:26:38ba9f2efd2e6ef3031895e641e3b68b8393e992916edee48590a5c5fb020085fazip  
2022-12-23 23:22:41d685319e95ac1bb62ec778345656832efa6b7f99c267d33915b043acab151271zip  
2022-12-23 22:10:02bdddccac73f6cc1884b1425578fe8a5e8eb7a9d25a229a852136bebb748f6248zip  
2022-12-23 20:40:056c0db030e07dea94900bf154d9c0628193fa7bdbc70a4e9c029b22ae6ee1663dzip  
2022-12-23 19:39:17f74a9cfe413640f2834f9e7ddc566df0531ade8c9686a20378d02dc84d0151a2zip  
2022-12-23 18:26:45f02bc2def275e4786195ae2ac62da716173cc8a3c22e45df6b4f6395f77e30e9zip  
2022-12-23 17:44:10ce564a4d81ce307fe67f9b5c9a85bed5aef94f17ab9808f2685ec4a5cdfdfcfdzip