URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: merchentusindiajute.com
Domain registrar:OwnRegistrar -
Domain registration date:2022-12-18 10:26:48 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-11-07 03:49:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-12-19 03:27:20 199.59.243.225Not listedAS16509 AMAZON-02- USno
2023-11-07 03:49:07 103.152.79.123server.perabytesserver.comNot listedAS140641 YOTTA- INno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-10 03:55:06https://merchentusindiajute.com/Goblin.exeOffline32 exe RedLineStealer ext zbetcheckin
2023-11-07 07:01:11https://merchentusindiajute.com/Kakadi.exeOffline32 exe LummaStealer zbetcheckin
2023-11-07 04:37:08https://merchentusindiajute.com/ss.exeOffline32 exe LummaStealer Stealc zbetcheckin
2023-11-07 03:49:07https://merchentusindiajute.com/Juderk.exeOffline32 exe RedLineStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-13 13:59:125f7a1ec42b23c893571fd3f31b493e138f9df1a3fbe6e2015b67604459a968b0exe RedLineStealer
2023-11-13 13:35:19d39b48b077c4bb9ed756ca0e022df081e07873a609e847b7bc23cc834fb1f57aexe RedLineStealer
2023-11-11 16:07:15551e4f5193b90e3f697ed2a9933e9d001451b4a59eb7e9e65d971078df28ababexe RedLineStealer
2023-11-11 14:51:52f93ff6a27dfff4e5340c76832d55e4c15e2724fd006cbe33cbddfb0efee8da7bexe RedLineStealer
2023-11-11 02:57:27a67fbbab953445f8609e6859844e5ee98f92d8c1d58b9e4fc8fd557798e6dd22exe 
2023-11-10 04:20:5935433be0d50d626d8cb7917f80c543b170f3d0219b70ab041fa1f61c8a984097exeRedLineStealer
2023-11-08 16:09:225ef4ef15a14b1ed32fc4b03fc252f92d107b93d2dc05eeb032574d796ab188e3exe RedLineStealer
2023-11-08 12:34:20d49e3fe3bd14ee37eadcbd6df61cffad9d6963e88b92cf5269361071ed429385exe LummaStealer
2023-11-08 12:16:563c2dda9881c9528f3739355e1b7162f5706ba7bd00502f523a520d1f1485954cexeStealc
2023-11-07 18:26:057d02e20a4a9672e842864c3abb108250296ac693e63151c8f2783a315b89ed19exeLummaStealer
2023-11-07 11:57:260762b2ba2bf925463ea8662e76030861754ab4d1c7aff8c1005d246921b35db1exeLummaStealer
2023-11-07 07:01:11523365b77d29365c6ac6df9ff8b270525fe9db7f59d505fcd153e646a036ef34exeLummaStealer
2023-11-07 04:37:081bcd064a8d5d8cb8e607c7b6b8a2575a9c7de02439477b9b77be747768ec9da2exeLummaStealer
2023-11-07 03:49:0789533b94d2a875986899cc238b54bd5a1df45f0beb6e0cfd12f588b121acd7fbexeRedLineStealer