URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | muriaspetin.es |
|---|---|
| Spamhaus DBL : | Abused domain (botnet C&C) |
| SURBL : | Blocked |
| Quad9 : | Blocked |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2025-04-27 18:44:03 UTC |
| Total malware sites : | 8 |
| Online malware sites : | 8 (100%) |
| Offline Malware sites : | 0 (0%) |
| Newest active malware site : | 2025-09-02 13:04:24 UTC |
| Oldest active malware site : | 2025-04-27 18:44:12 UTC (Age: 1 year, 3 month, 10 days, 12 hours, 6 minutes) |
| A record(s) observed : | 1 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 18:44:12 | 37.153.92.241 | eu-spain02.gestionesdns.com | Not listed | AS60494 Unelink | ES | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-09-02 13:04:24 | http://muriaspetin.es/wp-load/WickrMe.exe | Online | AtlasAgent ua-wget | |
| 2025-09-02 13:04:17 | http://muriaspetin.es/wp-load/Solana%203.0.exe | Online | LummaStealer ua-wget | |
| 2025-09-02 13:04:13 | http://muriaspetin.es/wp-load/Trackma.exe | Online | AtlasAgent ua-wget | |
| 2025-09-02 13:04:13 | http://muriaspetin.es/wp-load/Kmahjongg.exe | Online | LummaStealer ua-wget | |
| 2025-09-02 13:04:10 | http://muriaspetin.es/wp-load/OK_TEST_WORK.exe | Online | ua-wget | |
| 2025-09-02 13:04:09 | http://muriaspetin.es/wp-load/w937gs27h.ps1 | Online | ua-wget | |
| 2025-09-02 13:04:09 | http://muriaspetin.es/wp-load/LEDGER%20LIVE.exe | Online | AtlasAgent ua-wget | |
| 2025-04-27 18:44:12 | http://muriaspetin.es/wp-load/Rapidsvn.exe | Online | LummaStealer |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-09-02 13:04:24 | eb96ca17a4a1c2aa97dd6fb686a40cb226c49c8abec01190f1af75080a9aaa6b | exe | AtlasAgent | |
| 2025-09-02 13:04:17 | b96d62f1722f493a739f3344197f48847bc0ba09b40230cf998efb615871b1d0 | exe | LummaStealer | |
| 2025-09-02 13:04:13 | f3f0c87303fcc19aae446de0ff80560e09fdc1fc4b20b3dd442871b2544c5c7d | exe | AtlasAgent | |
| 2025-09-02 13:04:13 | f40b80a2809ee918dd4308317d4011a3ca87e2b92a3ab3d2fdaeef231d2e8510 | exe | LummaStealer | |
| 2025-09-02 13:04:10 | a523eba436c92fbbbd224db004793c9a1ca9abad540feaa0dd8044311212477f | exe | ||
| 2025-09-02 13:04:09 | f2f9de4523c4bca66339dabdfdcdb682ba71c32c977fa0564251f1fd619da0de | txt | ||
| 2025-09-02 13:04:09 | d8a9e5f8d5aadae72f01192ef172c704460a6f4c5eeff545d23d6c19327b9171 | exe | AtlasAgent | |
| 2025-04-27 18:44:12 | d0d387a7c32bfae33589ae9d1de850e39fede187e6f01182e5837a73cfd0c6d3 | exe | LummaStealer |
ES