URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ng.idiawarriorqueen.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-06-11 07:52:33 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :36

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-07-17 22:09:13 206.123.157.44Not listedAS9009 M247- AUno
2020-06-12 04:23:04 206.123.157.40Not listedAS9009 M247- AUno
2020-06-23 03:33:51 206.123.157.23Not listedAS9009 M247- AUno
2020-06-28 12:14:21 206.123.157.38Not listedAS9009 M247- AUno
2020-07-03 00:15:44 206.123.157.21Not listedAS9009 M247- AUno
2020-07-02 17:15:30 206.123.157.53Not listedAS9009 M247- AUno
2020-06-30 19:19:42 206.123.157.26Not listedAS9009 M247- AUno
2020-07-02 04:16:07 172.94.68.175SBL688689AS9009 M247- USno
2020-07-01 23:16:44 206.123.154.169Not listedAS137409 GSLNETWORKS-AS-AP- SGno
2020-07-01 22:16:54 206.123.154.135Not listedAS137409 GSLNETWORKS-AS-AP- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-06-11 10:59:07http://ng.idiawarriorqueen.com/css/chu/x6TmpkJC...Offlineexe MassLogger ext zbetcheckin
2020-06-11 10:45:12http://ng.idiawarriorqueen.com/css/bl/sadb8bQv4...Offlineexe MassLogger ext zbetcheckin
2020-06-11 10:44:36http://ng.idiawarriorqueen.com/css/ef/whYQBFCZk...Offlineexe MassLogger ext zbetcheckin
2020-06-11 07:52:36http://ng.idiawarriorqueen.com/css/ok/MnxI7xB3q...Offlineexe MassLogger ext gorimpthon

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-06-26 15:23:5720a8ad98bbfc7eb722f2bd392228cb6be745589c7d5bc6938dbd2d2983b01abfunknown  
2020-06-11 10:59:0703968a3a5a7a880feefca31686fcfbed445080a0c06eda2b6d623757179b782cexe MassLogger
2020-06-11 10:45:12a4cebe4913d275f7387b8d8b2acb7d76324550746e8802f28d432a15d3608194exeMassLogger
2020-06-11 10:44:36d76b4212f4b378be4ebac39567fb86df9b1bddffabf4e041d2e45503c441914aexe MassLogger
2020-06-11 07:52:359b5b44ded4ede28d92834c4db286780a5628d02597a739ff3633f808d47f0939exeMassLogger