URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: msedge.vg
Domain registrar:NICENIC -
Domain registration date:2026-03-25 09:46:19 UTC
Spamhaus DBL :Phishing domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-04-06 08:37:07 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-06 22:44:55 31.56.176.150Not listedAS56971 AS56971- FRyes
2026-04-06 08:37:09 176.65.132.185SBL679274AS51396 PFCLOUD- DEno
2026-04-06 15:43:41 31.57.118.10Not listedAS56971 AS56971- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-06 08:37:09https://msedge.vgOnlineascii CountLoader dropping-LummaStealer hta ua-mshta abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-10 11:28:1676add4d80d5b1db725bdec9015e770ba6646f93292e8e4070718f3113041df39hta  
2026-04-10 03:52:07d025e264505d006db88e8ffec9c98f034794ae35c2e4d42d9fe07505f99b095dhta  
2026-04-10 01:53:5234ded36b6c0255918a19b867378fc72f305f758f5884a39181cba4872f45905bhta  
2026-04-09 22:26:350772017df8ab0bfabbb0c01e2a337b9e45762c02ae62ccd2c75c7a488fec7978hta  
2026-04-09 17:30:415d152f92273524b9762e671796f3854ec14718b67429047aa8f63144a3c9e618hta  
2026-04-09 11:10:420505a96f118fc6a9413c3911ae8dee1ea2eb9d0d6caa8632b9373dfd18f06257hta  
2026-04-09 05:12:41822253ec5e51a70b6441e410d46669bc20cce227c8222d56ea64eb07fd02138dhtaCountLoader
2026-04-08 23:13:56a985f9bd239c8d1d78f2f8d3e4a60af6e5c5d822089f77e6936f0ed2a44e5ceehta  
2026-04-08 16:58:538e44388f0e0c96e2c4e7202a6205eef3c6f4dd7d2f5bef763c78bb881b6f4b3dhta  
2026-04-08 11:20:48789c41c6a71be39cd17063bc8c3443942833231e73739a872df9c084b03e79f7hta  
2026-04-08 10:35:39739fba1f797a5a21aadea6ea542e656b887ecfc15c327d0724234061f55fd3d9hta  
2026-04-08 04:07:2307252f6fd297bd07d13d3a879a2a1ba0658fbaed521ebedce9b301cfb593e508hta  
2026-04-07 22:21:213d5ad778ee2c5c5cd0772d0cdfa1518257873ac4224041cbc8b5d4245e4965c7hta  
2026-04-07 16:15:021c004c49a3c4cdbf5e9173cb0454040ecc1e69bbfbaee0da002f47a25b8e5fabhta  
2026-04-07 10:20:42cf2c2bfb302ec3f104846ad5d0ca260547276546ada7d60ca9b0b7797af17d49hta  
2026-04-07 04:25:4348ed0ef8516ee52de1d89ea719ad55a1006bb05447c89482546ba6c2a1371730hta  
2026-04-06 22:44:5467065b6619b5f349161a5554d2e87c6eef975e0bb4637b40df57fdba0879a652hta  
2026-04-06 15:43:406304c4a0a313f12380ccb91c152b429ea220ff7d3427dfe16ba86c31cb777224hta 
2026-04-06 08:37:09c2a70756124687f110305b33f59a58d604c36b0114c82088208d832a7b7becf7js