URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ns5004965.ip-51-79-228.net
Domain registrar:OVH -
Domain registration date:2019-01-23 10:58:16 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-08-06 12:49:06 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-06 12:49:15 51.79.228.20ns5004965.ip-51-79-228.netNot listedAS16276 OVH- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-06 12:49:19http://ns5004965.ip-51-79-228.net:17701/xlfrc64...Offlineua-wget BlinkzSec
2025-08-06 12:49:16http://ns5004965.ip-51-79-228.net:17701/10.exeOfflineCobaltStrike ext ua-wget BlinkzSec
2025-08-06 12:49:16http://ns5004965.ip-51-79-228.net:17701/88.exeOfflineCobaltStrike ext ua-wget BlinkzSec
2025-08-06 12:49:15http://ns5004965.ip-51-79-228.net:17701/nc64.exeOfflineua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-06 12:49:19fd10120afcad7ce9f20aed34679bbeef3173009f7b78caee40aae285512503d0exe 
2025-08-06 12:49:162df98b623cd8011af0d609879eefbff634b1ff9a36566de1f98b33411905c604exeCobaltStrike
2025-08-06 12:49:15ef4104e60bec9b76c4c170463700002f2fb0d7098fc0a5bd1e2947787b5319c0exeCobaltStrike
2025-08-06 12:49:133e59379f585ebf0becb6b4e06d0fbbf806de28a4bb256e837b4555f1b4245571exe