URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: node3ghost.ventaserv.in.net
Domain registrar:Public Domain Registry -
Domain registration date:1994-10-26 04:00:00 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-03-19 21:26:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-19 21:26:04 104.21.47.127Not listedAS13335 CLOUDFLARENETn/ayes
2026-03-19 21:26:04 172.67.171.36Not listedAS13335 CLOUDFLARENETn/ayes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-19 21:26:04https://node3ghost.ventaserv.in.net/verificatio...OfflineACRStealer ClearFake NetSupport ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-23 03:04:338e2f63960ffe5e9fddf3e01085991c422625972e24397f81dfc9c39f8fd6f771dllNetSupport
2026-03-22 21:13:0957be10355a8e39ae3d19dc8064292fe2729bbbd4b341ae48a3163d18d7148cb2dll NetSupport
2026-03-22 14:43:2028a1391840c705bdc20f52eead0884633e68fb3216c055da7e19d51f023c3030dll NetSupport
2026-03-22 10:39:08a0b9c5dd960c83312420fba8f64d0e4cfbb98bce4ecc1cfeab5dc3fd331385cadll NetSupport
2026-03-22 09:54:03c0bc5097977ed9491bd79d126845236cfd4bf09c09a3841c68fc28674e1bc91edll NetSupport
2026-03-22 03:55:5622aaf84df68eb05c0a112b42a9387a985473405a6fa86d6c7694b7c066124efddll NetSupport
2026-03-21 20:57:27156f07882475104c324ab065f228791f57b826b6e9ab212f658fb55b0c00c425dll NetSupport
2026-03-21 15:01:343604e386dcfa6c4d8316929538024adeb97cfecb478ab042a2efc378d7cb990fdll NetSupport
2026-03-21 09:57:56713f95a3ebdf4d45783683d67740c3fbbdb85e89f1b632e2af66c8deb388e6bbdllNetSupport
2026-03-21 03:12:252ef9973e259a0959f19ec1307928cc237945179226e8606b386d60cebca4143fdll 
2026-03-20 21:58:4580c16135a33e213bfa1cb8bb6cdbfdec0a654ba143b9377b7372f851a4841e1edllNetSupport
2026-03-20 14:42:20ecfaa155adf7b3d2421a9960b87773ba5e4fa0c0dcfea850378aaed1e0ced108dll ACRStealer
2026-03-20 08:55:56b6f56be41d055aabf359c8368e90a5f9b086588c00734d3074134dceec04aeb7dll ACRStealer
2026-03-20 06:50:14b0e1beb8efa31915bb0391e97993f6a6774feda87f1b61d67f9d3c8bb6308b12dllACRStealer
2026-03-20 03:09:369b109da752c7d3c94e769091a774cd76a1e5e2ed9d6b39cc92d5bf399626f6b1dll ACRStealer
2026-03-19 21:26:0476b4bbae58a2d240553c01fa0ae950527fb3009f983aceaaaa71649b4cdb4a7cdllACRStealer