URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: protestlabsmovings.es
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-11-10 11:18:02 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-07-16 11:20:15 104.223.143.70Not listedAS16509 AMAZON-02- USno
2020-07-10 01:16:07 67.43.239.171Not listedAS36666 GTCOMM- CAno
2020-07-07 11:33:30 185.189.112.191Not listedAS9009 M247- DEno
2020-06-30 20:19:32 104.223.143.93Not listedAS16509 AMAZON-02- USno
2020-06-02 15:16:49 46.21.147.17546-21-147-175.static.hvvc.usNot listedAS29802 HVC-AS- NLno
2020-05-11 15:35:12 45.14.112.101Not listedAS3170 VELOXSERV- GBno
2020-01-21 17:49:49 104.223.170.113Not listedAS16509 AMAZON-02- USno
2019-11-29 18:01:40 104.148.41.60Not listedAS16509 AMAZON-02- USno
2019-11-23 18:50:05 104.148.41.16Not listedAS16509 AMAZON-02- USno
2019-11-10 11:18:09 213.108.198.204Not listedAS216475 nktelecom- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-10 16:55:09https://protestlabsmovings.es/rukop/wnrCLqWI1j9...OfflineAgentTesla ext exe abuse_ch
2020-06-30 20:19:32https://protestlabsmovings.es/domry/LIjJHBNFy.exeOfflineexe Loki ext abuse_ch
2020-05-11 15:35:12https://protestlabsmovings.es/trilp/build_QaDIy...Offlineencrypted GuLoader ext Loki ext abuse_ch
2019-11-10 11:18:09http://protestlabsmovings.es/mgbohy/Frityp.exeOfflineexe Loki ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-11 15:58:16912861dd71bda93e31e1e703f29d73eef374d3ef24bc4170d21132f088884d92exe AgentTesla
2020-07-11 07:17:22a3009b66e611127884db7d845017ace8c556820e757e97993abc312b62a11ecdexeAgentTesla
2020-07-10 18:43:0528b754fa7438d0186ad750f74e6ad182e11d8aa5f6566793ac73b393a4b30276exeAgentTesla
2020-07-10 16:55:09160e88f42b6a24d4a995142e7e6288f44bf85fbf1afcc0dd9ff4931bd9bc82f2exeAgentTesla
2020-07-02 01:51:157afb56dd48565c3c9804f683c80ef47e5333f847f2d3211ec11ed13ad36061e1exe  
2020-07-02 00:16:4255388e13d65ddcd067ba248d76628b6ebbdb1a51fbcef36589d11604fb3a0e54exeLoki
2020-07-01 18:55:251df4c75f2c8119a401b59d5954a031c0af8490764a7127dcd02185b27154162cexeLoki
2020-07-01 16:20:321feb6a5f318bf4076cd084cd271d697491cb897e1ab91d397d7f08f66d2e1799exe Loki
2020-07-01 15:37:521f39849a2b65f4a84501e900aa8226f4ab93f89a51203640a77c6c33cb470589exeLoki
2020-07-01 14:44:1669f1c09a3db83dae38ff8fb5f323689ac245b2bde06133d49d33d1e05ada8b7fexeLoki
2020-07-01 14:34:16e4aa32ccbd12c96a8f49039a2e2e7395089a0cb9a524ba38dc33f8066275482cexeLoki
2020-07-01 12:39:30d1a78264bce1e629719b047552173eb7b6a4805b2cf1d92de0231d7762dbc224exeLoki
2020-07-01 11:18:20551d0cab361858a7aabce4f156aba860a3e40a4a17962a0b5b822402b37b4305exeLoki
2020-07-01 09:25:27f1ff4a8c0b69b04ac52186300cc66f5c122ab87ff70d757211ccc049013299e4exeLoki
2020-07-01 06:56:292c249db68985414c6d06f92cc5b113657fe7f3b6f647a7119147bd8fbbf95f82exeLoki
2020-07-01 00:05:48950afdfc712687ef06676b890a73936fecf980e947f9f2f0d36ea89dc6b3f40cexeLoki
2020-06-30 23:30:41ff9ebbc66b229b2170d67b4475d64d0eba2a6c01ff8ad155299985d32149e2e1exeLoki
2020-06-30 21:12:4031b2092367fc66eddbde56095bed49cc271d7a6e388b1f70951bd27cc4fa3c9aexe Loki
2020-06-30 20:19:3106384ff303fadeb1b7f8a3eb85b996cdb4e738f30397e927da65204649056e8dexeLoki
2020-05-11 15:35:12d2e017d1088f12a5c841f7eb20c743965f3cd6f8d9cb06b39e05fe4f6eab3a0aunknown  
2019-11-11 19:41:334bd34301092b32567930a690b77b2341cc4e48be131f735098987be62fbd5428exe Loki
2019-11-11 16:24:22dbb13b8375f032e1549bc5469f261076439822fd2967921cffea3ac25f65354bexe Loki
2019-11-11 13:25:3176f5382294619ddf7df60b12e706dead2fa1d2988b2721488848d6b31f7a32c1exe Loki
2019-11-11 00:12:121024baeefe54ba599f925f49fa7a19470bef896cd9ae894c1f721b7d78f3715bexe Loki
2019-11-10 20:18:33eae4a6a3711cb56d463dd0990dbd69948e61bfcae5aadfbf9cadb9489f8f96c2exe Loki
2019-11-10 18:14:312e4792c7f5d828e310ce9cf2b7446e137d4033339a38fd15409bdbdf9cd0decbexe Loki
2019-11-10 16:52:47fd7bf26f625259baa40c0ffaf193eba0f72c01e99a83b752b8546a231dd8d548exe  
2019-11-10 16:15:24acb2866a268a1814d9e67da6b151e494ffa21498b3b37d57d0bb8ad7c525ee94exe Loki
2019-11-10 13:35:3382a8653192b32aa5215458ed3518e3ef38c022de0c0c91119d22c73f184a592aexe Loki
2019-11-10 12:37:26e1189905a962cbfbbd4e5d0e69a0cd7a12cdf1b47608e95899103a98675efa10exe Loki
2019-11-10 11:18:072b8895004f21ae10dd35787385807ea83303eb8730f4a6375f159a7788bef7bcexe Loki