URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: paymetconfirm.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-21 18:09:04 UTC
Total malware sites :42
Online malware sites :0 (0%)
Offline Malware sites :42 (100%)
A record(s) observed :22

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-13 05:57:46 63.141.242.46Not listedAS33387 NOCIX- USno
2022-10-10 21:38:55 81.17.18.196hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-10-10 01:01:17 81.17.29.148hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-10-10 13:49:19 81.17.18.194hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-10-10 00:07:43 63.141.242.44Not listedAS33387 NOCIX- USno
2022-10-10 07:55:39 192.187.111.222ehy.qwiqo.liveNot listedAS33387 NOCIX- USno
2022-10-10 06:46:17 192.187.111.220jyt.qwiqo.liveNot listedAS33387 NOCIX- USno
2022-10-10 01:44:26 81.17.18.198hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-10-10 08:03:13 81.17.29.147hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-10-10 03:45:57 81.17.29.146hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-27 21:15:44http://paymetconfirm.com:8088/wp-theme/xpt9.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:15:26http://paymetconfirm.com:8088/css/FICvR.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:14:31http://paymetconfirm.com:8088/templates/MfbNKrx...OfflineDridex ext Cryptolaemus1
2021-07-27 21:13:59http://paymetconfirm.com:8088/app/QHXu.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:13:06http://paymetconfirm.com:8088/uploads/MfbNKrx.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:09:52http://paymetconfirm.com:8088/images/LTBH9TA.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:09:13http://paymetconfirm.com:8088/app/0oU1n.pngOfflineDridex ext Cryptolaemus1
2021-07-27 21:07:07http://paymetconfirm.com:8088/app/FICvR.pngOfflineDridex ext Cryptolaemus1
2021-07-21 20:46:08http://paymetconfirm.com:8088/js/Invoice_464705...Offlinedr Dridex ext excel zbetcheckin
2021-07-21 20:31:06http://paymetconfirm.com:8088/img/Invoice_48021...OfflineDridex ext excel zbetcheckin
2021-07-21 20:30:06http://paymetconfirm.com:8088/style/Invoice_555...OfflineDridex ext excel zbetcheckin
2021-07-21 19:24:07http://paymetconfirm.com:8088/templates/Invoice...OfflineDridex ext excel zbetcheckin
2021-07-21 19:24:05http://paymetconfirm.com:8088/tpls/Invoice_9255...OfflineDridex ext excel zbetcheckin
2021-07-21 19:24:04http://paymetconfirm.com:8088/style/Invoice_730...OfflineDridex ext excel zbetcheckin
2021-07-21 18:25:01http://paymetconfirm.com:8088/javascript/oQE8Qo...OfflineDridex ext Cryptolaemus1
2021-07-21 18:25:00http://paymetconfirm.com:8088/wp-content/MfbNKr...OfflineDridex ext Cryptolaemus1
2021-07-21 18:24:59http://paymetconfirm.com:8088/uploads/EOIxmku.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:58http://paymetconfirm.com:8088/files/h8f6.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:55http://paymetconfirm.com:8088/img/Kbf2P.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:52http://paymetconfirm.com:8088/css/1d6vP.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:50http://paymetconfirm.com:8088/wp-theme/oQE8Qo7.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:45http://paymetconfirm.com:8088/wp-theme/b486Pv.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:45http://paymetconfirm.com:8088/files/m0gy97Q.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:42http://paymetconfirm.com:8088/js/xpt9.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:40http://paymetconfirm.com:8088/app/biJze.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:40http://paymetconfirm.com:8088/css/QHXu.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:40http://paymetconfirm.com:8088/js/h8f6.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:38http://paymetconfirm.com:8088/files/Kbf2P.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:37http://paymetconfirm.com:8088/uploads/1d6vP.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:36http://paymetconfirm.com:8088/js/FICvR.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:36http://paymetconfirm.com:8088/tpls/EOIxmku.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:33http://paymetconfirm.com:8088/javascript/h8f6.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:31http://paymetconfirm.com:8088/images/Kbf2P.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:30http://paymetconfirm.com:8088/js/biJze.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:27http://paymetconfirm.com:8088/js/UuqDiHK.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:26http://paymetconfirm.com:8088/wp-theme/0oU1n.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:25http://paymetconfirm.com:8088/wp-theme/QHXu.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:23http://paymetconfirm.com:8088/style/b486Pv.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:11http://paymetconfirm.com:8088/css/xpt9.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:10http://paymetconfirm.com:8088/images/b486Pv.pngOfflineDridex ext Cryptolaemus1
2021-07-21 18:24:09http://paymetconfirm.com:8088/javascript/LTBH9T...OfflineDridex ext Cryptolaemus1
2021-07-21 18:09:05http://paymetconfirm.com:8088/img/EOIxmku.pngOfflinedll Dridex ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-23 07:36:2163936cb0159cb6ca6af3e2d7cbe48152e8080bbfc61e39e8a78f0d52de058b83doc Dridex
2021-07-23 02:19:43f49cfbe13317efbfdf48b79f235e9b9e9d3a72e63c1d274428959f67f0c7eec9doc Dridex
2021-07-22 17:43:074aa2319b7a3c2b24bb3822a4819085ec6b980b48e7df30fa51e4abcc9b47c381doc Dridex
2021-07-22 15:20:54ccd127bb1db5de023c7c65f487acf5490bc977ca1c0869b71e89056b1b547dc1doc Dridex
2021-07-22 12:36:48add99a297f6cb241dd6b608a7c3a78a7c984a712a9c05d7a973aa871084103addoc Dr
2021-07-22 11:14:49e93a6d88d266a287750737821d91c9e48fa0aadafbc14ad191dca5d2ba82a3d0doc Dridex
2021-07-22 07:51:026b00c17c42fa5d9c0638c512766f955d5b16facdd3e535424a91f494bd6fc2fddoc Dridex
2021-07-21 23:09:442645dd428205aa4b86308692a66988e76986165fcdf819df4c77964c9fa0de7cdoc Dridex
2021-07-21 20:46:08fdd4ee9e0e1f197e66f1efae2ce26db6ef0a1fa0867f9316c3cdb288fff6690fxlsDridex
2021-07-21 20:31:06b11c33ee5fd193e6548d14c2bde4865d30d6d5fd25135bc258cfd8595ae3695cxlsDridex
2021-07-21 20:30:0663ec2a80765669b56d7d440ccf344be2aaac3f25badfe61f62cb660170f2f3a0xls 
2021-07-21 19:24:074fc754bd7957493e0b8e127e22cb4599f9ad57d8a581087cd697ae9ee90e6d55xlsDridex
2021-07-21 19:24:04413934e841b46e2dba1902765b5c49d2386736af1492ae274ccb0e50353a388bxls 
2021-07-21 19:24:044a8c152ef7c7e3ced93e8629691f6f66bb67f78c4e17caf0198db18300b19acfxlsDridex
2021-07-21 18:25:0155bc0af1e99d0310ea3e8668aba02e4d3aa3c800b85fe304a6377968a4668cc1dllDridex
2021-07-21 18:25:003cba24dba02d5817a029caee6eadf1b3b4eb75ff861c62df3e4d4fbde1c349c2dllDridex
2021-07-21 18:24:592c54438f5d99d15e5df3965397e25a0fa17ca7f08d317eb4bf31d1268e10f020dllDridex
2021-07-21 18:24:581a560adb810b924e65f91e34664166be2c2adac10f7f28c075d902e4adb1112cdllDridex
2021-07-21 18:24:55e26c7e7c111e41d766ab313e1c4c0f17cbc9710aee23248b017735caf97f2a0edllDridex
2021-07-21 18:24:52537866a96449444a54002776f34eecf053c23122a554a79f4743df0749aa8005dllDridex
2021-07-21 18:24:4955bc0af1e99d0310ea3e8668aba02e4d3aa3c800b85fe304a6377968a4668cc1dllDridex
2021-07-21 18:24:45ec705e006b4074a61b4b001660ce083e1948bb7ef17c69a90ad5ef5bb635d132dllDridex
2021-07-21 18:24:4584c54cd76f3ac50f2f2e4afa57802d576bc5dd3c92cde50850feb04e02461ba3dllDridex
2021-07-21 18:24:42ef08eafe517a3af06bb806865de42aac88231aac2e1462fa5b44b0db7231cf28dllDridex
2021-07-21 18:24:40ff277a5e33ec98ad5f0945834f731e39fa2113ac0369ade14fc690a9d1a7cc31dllDridex
2021-07-21 18:24:4080012d65f11c6481e6e98a03016f5a69ed2ae210af24d810b7ce562318a9b116dllDridex
2021-07-21 18:24:401a560adb810b924e65f91e34664166be2c2adac10f7f28c075d902e4adb1112cdllDridex
2021-07-21 18:24:38e26c7e7c111e41d766ab313e1c4c0f17cbc9710aee23248b017735caf97f2a0edllDridex
2021-07-21 18:24:37537866a96449444a54002776f34eecf053c23122a554a79f4743df0749aa8005dllDridex
2021-07-21 18:24:36f2c2d92afa0f167bd54c763fc8fc3377bb6b9f1105b4bd0760c5a19018c41c3cdllDridex
2021-07-21 18:24:362c54438f5d99d15e5df3965397e25a0fa17ca7f08d317eb4bf31d1268e10f020dllDridex
2021-07-21 18:24:331a560adb810b924e65f91e34664166be2c2adac10f7f28c075d902e4adb1112cdllDridex
2021-07-21 18:24:31e26c7e7c111e41d766ab313e1c4c0f17cbc9710aee23248b017735caf97f2a0edllDridex
2021-07-21 18:24:30ff277a5e33ec98ad5f0945834f731e39fa2113ac0369ade14fc690a9d1a7cc31dllDridex
2021-07-21 18:24:27770cb2aa5ea76f90e27bc72110b531fa3985ab4352d25362926971285408f148dllDridex
2021-07-21 18:24:26bacdb1cfcda34da7422c74810016d80179dc453b29d0121db596fc5346d98caddllDridex
2021-07-21 18:24:2580012d65f11c6481e6e98a03016f5a69ed2ae210af24d810b7ce562318a9b116dllDridex
2021-07-21 18:24:23ec705e006b4074a61b4b001660ce083e1948bb7ef17c69a90ad5ef5bb635d132dllDridex
2021-07-21 18:24:10ef08eafe517a3af06bb806865de42aac88231aac2e1462fa5b44b0db7231cf28dllDridex
2021-07-21 18:24:10ec705e006b4074a61b4b001660ce083e1948bb7ef17c69a90ad5ef5bb635d132dllDridex
2021-07-21 18:24:09b09882743ed13b041f6b2693943533e4be1e9a5d7e17b701d978d3f4178b76a8dllDridex
2021-07-21 18:09:052c54438f5d99d15e5df3965397e25a0fa17ca7f08d317eb4bf31d1268e10f020dllDridex