URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mrfreeman.shop
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-12-01 09:35:10 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-02 05:08:57 47.76.127.217Not listedAS45102 ALIBABA-CN-NET- HKno
2025-06-02 05:08:57 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2025-06-02 05:08:57 8.218.208.240Not listedAS45102 ALIBABA-CN-NET- HKno
2022-12-01 20:47:26 5.206.224.61lukslab.comNot listedAS47674 NETSOLUTIONS- PTno
2022-12-01 09:35:12 45.8.144.98milton.example.comNot listedAS209847 THE- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-02 01:25:13http://mrfreeman.shop/DgxuGixWrsAdtx/avicapn32.exeOffline32 exe LaplasClipper zbetcheckin
2022-12-02 01:09:10http://mrfreeman.shop/nppshell32.exeOffline32 AsyncRAT ext exe zbetcheckin
2022-12-01 09:35:12http://mrfreeman.shop/DgxuGixWrsAdtx/wevtutil.exeOfflineexe RedLineStealer ext SystemBC ext vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-05 13:01:5650a156c3f0896574896914d6943e851c81599e03e319d505f327eacc96fa6546exe  
2022-12-05 10:44:41630c8683a14364d7922574039f48d4c5763db300336b326716385e3c557ac479exeLaplasClipper
2022-12-05 10:41:05e27ac6756cbebfb6679f7f6b8428aa24efca10a089aaf582f14b3b07ef1d044bexe RedLineStealer
2022-12-05 09:54:16fa669ba964bed83adc5ba714c1ad13f3f1458685f1dfb7f15b1153287f918395exe  
2022-12-05 01:56:361d374ffd6bca52ab6e3b87864dcc5a14b396266c02e886756f55524a7af47b9dexe  
2022-12-05 01:21:5822d356755eee957f75b09e389ec629da6988502275bba71cd7f600a53033ba3aexeRedLineStealer
2022-12-04 00:20:32878f26886d0cb4d45c8072e97f10a5406f07ad7163c8dfd2dd61b81a58c85215exe  
2022-12-03 22:42:55261711de27d5ff2dca6ab8a29d6c71dc2f897b8f9fe93be7f7a499f46e5caad0exeAsyncRAT
2022-12-03 22:38:0201ef194861611da3374baa47765dd98f4133a2317a8cf16674c7f42b45f0cb4eexe  
2022-12-03 22:28:260f4bef20f214d4f9b6a5f189201ee69ca330a91accbd8253a15676d86b1aa4c2exeSystemBC
2022-12-03 01:44:167b6637b2e136f7d7faa5d8a860e7849896ce548a6681840df2adacb23808782dexe  
2022-12-03 01:08:423e8e78921c85f9fcf7b053b6e4da0ed7f5a47abb22ebb1fd12c68485df6be9b7exe  
2022-12-03 00:50:28c0d148914e1c4d73ed16addd530a0cc30a3818bdf7d99eac1643252d8b37cac9exe  
2022-12-03 00:38:435371907d2d8f6ca5c4c595f65929fd2b0434d11ba82d7939030a38759367f1dfexe  
2022-12-02 01:25:13d2ca311fbe4e597f29e25b9e1992b796a6fdbf5b3181ee7fc95caac508679c81exeLaplasClipper
2022-12-02 01:17:33e774b64170ea54274f9193e871da0412fa53835451f2f26277d9a474ff1ae7d5exeSystemBC
2022-12-02 01:09:101cd90a306cb04ddc66545e47d7ca55d2bbc1dc0877d79f0cdfabadedc43f87e7exeAsyncRAT
2022-12-01 10:52:50691de4b62a44a670c721c4015a854c157d73be1bf96e412133b0d1ea7124ae4eexeRedLineStealer
2022-12-01 09:35:12e5e3a8a79f5d94cf3653932e942ce03e02145060328a0c82f0049c5f558b9dd3exeSystemBC