URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: portalconnectme.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-06 11:25:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-02 03:02:59 89.40.10.23s2.web.xgamefan.comNot listedAS212531 Interneto-vizija- LTno
2020-04-25 01:10:01 47.74.90.81Not listedAS45102 ALIBABA-CN-NET- USno
2020-04-21 19:05:15 89.47.167.1913mjn.l.time4vps.cloudNot listedAS212531 Interneto-vizija- LTno
2020-04-20 11:03:15 47.254.24.12Not listedAS45102 ALIBABA-CN-NET- USno
2020-04-16 05:41:01 89.47.161.36www.bcdewubbos.beNot listedAS212531 Interneto-vizija- LTno
2020-04-15 07:07:05 45.89.67.19214ipv6.okNot listedAS209641 I-SERVERS-EAST- RUno
2020-04-10 13:20:17 3.120.31.229ec2-3-120-31-229.eu-central-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- DEno
2020-04-09 04:16:27 107.180.238.68ip-107-180-238-68.nodes.dream.ioNot listedAS26347 DREAMHOST-AS- USno
2020-04-06 11:25:05 47.74.67.231Not listedAS45102 ALIBABA-CN-NET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-06 12:18:46https://portalconnectme.com/server_encrypted_6E...Offlineencrypted GuLoader ext abuse_ch
2020-04-06 11:25:05http://portalconnectme.com/king.exeOfflineexe GuLoader ext cocaman

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-06 12:18:4557cc45c4a3e1ce92c5fb4e970e16334dd4db47858607b7e7f26388f0d2f83f70unknown  
2020-04-06 11:25:0491dfd41acf3e4f461c8c0c5ffdad45e08e92c839dd4f4f233b3e0ff57efd5064exeGuLoader