URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nestlex.tk
Domain registrar:Freenom -
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-23 13:57:03 UTC
Total malware sites :10
Online malware sites :0 (0%)
Offline Malware sites :10 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-10-13 08:34:09 2.56.59.211Not listedAS3758 SINGNET- SGno
2021-10-07 17:12:32 195.133.18.140Not listedAS205007 ESERVER-RS- CZno
2021-06-23 14:18:30 185.239.243.112ns1.20mb.nlNot listedAS212238 CDNEXT- USno
2021-09-17 08:06:00 104.248.32.225food.bornfight.devNot listedAS14061 DIGITALOCEAN-ASN- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-10-12 16:32:06http://nestlex.tk/mazx.exeOfflineexe Formbook ext abuse_ch
2021-10-11 18:47:05http://nestlex.tk/famzx.exeOfflineexe Formbook ext abuse_ch
2021-10-11 18:22:04http://nestlex.tk/templezx.exeOfflineSnakeKeylogger ext AndreGironda
2021-10-11 14:20:06http://nestlex.tk/obinnazx.exeOfflineexe Formbook ext ffforward
2021-10-11 10:20:09http://nestlex.tk/harshmanzx.exeOfflineexe Formbook ext abuse_ch
2021-10-08 05:14:06http://nestlex.tk/mavzx.exeOfflineAgentTesla ext exe Formbook ext abuse_ch
2021-10-07 19:56:07http://nestlex.tk/obizx.exeOfflineexe Formbook ext abuse_ch
2021-10-07 08:09:04http://nestlex.tk/nwamazx.exeOfflineexe Oski OskiStealer ext abuse_ch
2021-10-06 18:14:03http://nestlex.tk/bluezx.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-06-23 13:57:04http://nestlex.tk/hussanx.exeOfflineGuLoader ext James_inthe_box

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-12 17:07:1351d534b716e35b643ac2a4aa73effe9607abfc61a36b7b4a423c9383002b755eexeFormbook
2021-10-12 13:48:039f30d57fc655ec6f960bccde03a26d7af12839c55d6051aad379368881510f33exeSnakeKeylogger
2021-10-12 12:37:46ff64ff314c7947e5faae8181ac818b124a6d17d0fc3a66e8777a78a613d6093cexeFormbook
2021-10-12 12:28:28d43f8c736bd68c607021e9867d0c2e942b94bb1e8a5c5dc9804f9109148b21e3exeAgentTesla
2021-10-12 08:39:30f2a5c2addef1471e98841eb5f2abbc5cd27c360f8850a69ef0a233d07744a9b8exeFormbook
2021-10-12 08:11:03b877e6f41d83c546f056fa7f88b5f323d944616a9919025e71971d034b56b592exeFormbook
2021-10-12 08:09:524a028b7f272dd96c75716d2268b551576a01ebccaca97bb19da43ec21dbe8514exeFormbook
2021-10-11 18:47:043c5d2a990e487ad59a140909b2e6047494467b163f6696be5e247f644e4c3210exeFormbook
2021-10-11 18:22:04e1a998ebde58e307397c9446947fe0b10dee23f730388734331388b1184029cdexeSnakeKeylogger
2021-10-11 14:20:0676cd5f994be53f3f24e2b2018263b9ab582e84870ee8d24f38c6d11adae3688cexeFormbook
2021-10-11 10:20:0922a5161a4d95e737100936f93042049719d13a8437d751c22ad485ed51ee7c96exeFormbook
2021-10-08 05:14:064b8143fc8d8d9ffc0efdc2eaf1e66a15c3ff56cd7e53429083f5fb908f5b9c67exeFormbook
2021-10-08 01:47:344acff00f1935efe2a12c8537de8b10c33bd714a07a8cdaafb56459f368acc669exeOskiStealer
2021-10-07 19:56:07dfbb8dc13848a4763fddee0be94415ef938755656c54e3f151995e2d50f251dcexeFormbook
2021-10-07 08:09:041ad022fe6f175e63e599e94fcc39c0e909e4f733f34e290dd3a6ce9692aa2f33exeOskiStealer
2021-10-06 18:14:0309f0b5fc12a7e772802d521bc82025a39be6ad148067648108e61f795ebb841dexeSnakeKeylogger
2021-06-23 13:57:037f347545daf832b84a0cb2d823af46e874cb7c69f436814c58355262e594c4d3exeGuLoader