URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: npaperjoy.com
Domain registrar:Namecheap -
Domain registration date:2024-02-17 18:02:04 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-07-10 01:52:05 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-07-10 01:52:09 199.188.206.52server321-5.web-hosting.comNot listedAS22612 NAMECHEAP-NET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-10 08:14:06https://npaperjoy.com/new/a.exeOffline32 exe NanoCore ext zbetcheckin
2024-07-10 07:25:13http://npaperjoy.com/new/c.exeOffline32 exe NanoCore ext PureLogStealer zbetcheckin
2024-07-10 01:52:10http://npaperjoy.com/new/a.exeOffline32 exe NanoCore ext zbetcheckin
2024-07-10 01:52:09https://npaperjoy.com/new/c.exeOffline32 exe NanoCore ext PureLogStealer zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-17 04:08:431c200baffc2c2b9a299a0a8e431634bbb12160f74601f85df81a9d8ab6ea62aeexe PureLogStealer
2024-07-17 02:33:49abcb43cb648a9e661c1bdd5f1372e51a84a3c2d8fc4043514eac1a8125164a8dexe NanoCore
2024-07-16 04:14:50ba74ee9700278dc54317982d9d382cf67e2132b4f388c040051812dd42efa17bexe NanoCore
2024-07-16 04:09:17d3f7e200327d65a5f4304f30f5795b37bef0d5f0ab3cc7ae9a29785382277c64exePureLogStealer
2024-07-16 04:02:18ba74ee9700278dc54317982d9d382cf67e2132b4f388c040051812dd42efa17bexe NanoCore
2024-07-16 03:38:24d3f7e200327d65a5f4304f30f5795b37bef0d5f0ab3cc7ae9a29785382277c64exePureLogStealer
2024-07-15 17:03:16c556eda3dbf9f7739263f46057b3073ba7c76f3028dacef54fb5a8715950551eexe NanoCore
2024-07-15 10:03:10d018983432f75f7768fa0f60416f3f3ddac67eb14cbd10ab0d46ac6abe619fa6exe PureLogStealer
2024-07-15 04:39:49d018983432f75f7768fa0f60416f3f3ddac67eb14cbd10ab0d46ac6abe619fa6exe PureLogStealer
2024-07-15 03:17:18c556eda3dbf9f7739263f46057b3073ba7c76f3028dacef54fb5a8715950551eexe NanoCore
2024-07-12 03:36:09424bfb9e5e118e9ac86ab13718fa81049b9c7c3a6b08f6bc41040e2faadef5b2exe NanoCore
2024-07-12 03:17:598051c628e55f885bf79ebd90bc8af52eb3451f1d4ce362f810459a91f45d40b4exe  
2024-07-12 02:53:408051c628e55f885bf79ebd90bc8af52eb3451f1d4ce362f810459a91f45d40b4exe  
2024-07-12 02:34:28424bfb9e5e118e9ac86ab13718fa81049b9c7c3a6b08f6bc41040e2faadef5b2exe NanoCore
2024-07-11 07:56:5874b5c4b71fb6634b2db9c8501147f6511a376d39dacdfd862d5cd41bf2a7cb08exeNanoCore
2024-07-11 07:52:17319bff6d833601a7f1db75dc79c6cd3f0df55c67c52fd989d5c1bf1b5ef5bc69exe  
2024-07-11 07:27:22319bff6d833601a7f1db75dc79c6cd3f0df55c67c52fd989d5c1bf1b5ef5bc69exe  
2024-07-11 07:15:4374b5c4b71fb6634b2db9c8501147f6511a376d39dacdfd862d5cd41bf2a7cb08exeNanoCore
2024-07-11 03:14:44ff02ce95ce92934b9bd5ab657c70a93909e35194c4efcd6105add3dc2fe74f5eexeNanoCore
2024-07-11 02:54:58ccdfb9ebd343553c8c058f37426d36084def7115ec228a6c51452dd26141573aexe NanoCore
2024-07-11 02:19:49ff02ce95ce92934b9bd5ab657c70a93909e35194c4efcd6105add3dc2fe74f5eexeNanoCore
2024-07-11 01:48:35ccdfb9ebd343553c8c058f37426d36084def7115ec228a6c51452dd26141573aexe NanoCore
2024-07-10 08:14:06b3ecfad7812c038effe03852fe7794bd52d291a97d858245c48ba8fd8408e131exeNanoCore
2024-07-10 07:37:37b3ecfad7812c038effe03852fe7794bd52d291a97d858245c48ba8fd8408e131exeNanoCore
2024-07-10 07:27:12ac5e61786802fec0c00c05fa0af6310a8968939dd0fd73eb105562bd72b04d1eexePureLogStealer
2024-07-10 07:25:13ac5e61786802fec0c00c05fa0af6310a8968939dd0fd73eb105562bd72b04d1eexePureLogStealer
2024-07-10 01:52:10535a76b11d8e55c1b67db48a5e19521233c2a877f83b65fb6e7edca3257e4a55exeNanoCore
2024-07-10 01:52:0939acd505663ef230a0871108eb33536dd87367ef886c1f209784e7434a930346exePureLogStealer