URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: purefoe.top
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-03-09 12:11:08 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-19 08:17:58 8.210.119.33Not listedAS45102 ALIBABA-CN-NET- HKno
2021-04-18 08:28:33 34.125.228.4646.228.125.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-04-17 10:56:22 45.32.195.1345.32.195.13.vultrusercontent.comNot listedAS20473 AS-VULTR- USno
2021-04-15 09:52:01 34.95.128.4444.128.95.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- BRno
2021-04-01 12:39:02 34.89.96.219219.96.89.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- GBno
2021-03-23 19:49:20 34.90.10.141141.10.90.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- NLno
2021-03-23 18:14:28 34.90.236.225225.236.90.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- NLno
2021-03-23 16:57:53 35.228.112.1818.112.228.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- FIno
2021-03-16 21:22:26 34.107.5.3838.5.107.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2021-03-14 08:15:02 34.77.2.213213.2.77.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- BEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-10 08:33:07http://purefoe.top/bestof/gfersd.exeOfflineexe abuse_ch
2021-03-09 12:11:14http://purefoe.top/bestof/gfers.exeOfflineexe RedLineStealer ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-02 14:07:147b31e9a3eb1d1b86583a4ce6df3e7acc24fac0c6ad9bf484b0158a508476c7b8exeRedLineStealer
2021-03-31 20:34:43127094ebdef2ba4286949a781d2d756ddc8ae76b42e14b0ba49da4ba6d191444exeRedLineStealer
2021-03-30 18:46:04dac8697e24dbe30b33cc0de5ac7584319b134ad59d11aeffdecb861a6868a8a3exeRedLineStealer
2021-03-30 01:10:0616ef7729e2bc71fd3b55f6772025a82a4fd6f049f5faa81da8466a8ba5bbe24eexe RedLineStealer
2021-03-27 21:31:28dc588705c74d26785a3bce4a0f58e5f722dc9851b7591f62fbbe406aab2ca955exeRedLineStealer
2021-03-26 15:53:52dc05f8eef2d694a880ced4170a493a9d0aeacc122f671bedd44fb8bba4b320f5exeRedLineStealer
2021-03-26 00:20:484879b5e9fe8c26e10594ed4c9a15410d4f2a1d85ca0125d1af7ba0287cd3cbcbexe RedLineStealer
2021-03-24 14:12:28c7d64e661c96d03e4b08bf7edb1e9667743133eb72207f19ebfe3f4cb6c7a4b7exeRedLineStealer
2021-03-23 17:23:5482c688930586c5afd7db267a158b8cac7d7efab22c14ec217cdb006a19c04b35exeRedLineStealer
2021-03-20 22:27:4235aac4dc4ab85c75852a93a573b654f275e6c1dcaae69cc3176c05271a097750exeRedLineStealer
2021-03-19 21:17:24807e65fc407c3d9f024b10e8cfb20c2e10ad067aa217fe97ec1b075c24dbc936exeRedLineStealer
2021-03-18 11:30:087eefafe85ed6277d9c6abd81fa1ef7969c2ce6767c609baafc79206f78d13685exeRedLineStealer
2021-03-17 23:55:53fd38d6e7ee598b9ead8640b414b0251e85b8cdd7c59ee456ea5ef973b476b3ecexeRedLineStealer
2021-03-17 01:34:24254f8a160343897dc3e748af2f4c2164455afe3daaa75654c0a7e13483a43f0cexeRedLineStealer
2021-03-14 20:47:30861a237188f0e380646af2228e4330d1fbcabae18da1e4593f562ac2f617e88fexe RedLineStealer
2021-03-14 20:19:16ca3f25030ff8f3c92d29caa22bae001d1d795a0ea2289cae3074679d86341b2fexeRedLineStealer
2021-03-14 18:47:36369e3c4b6730652146d275cd3db45eaa369c25fcaad3b11cdd3844878193768eexeRedLineStealer
2021-03-14 00:26:43bd824ea4c4eda6ab14aa271fa88dae5e1102d4cbaae86d46e47b80be0247d11aexeRedLineStealer
2021-03-12 02:06:032b65f398247039abc85b2742607f828b0516be3a63be7fae80608c30f649f0ceexeRedLineStealer
2021-03-12 01:55:140e498e6cc7dcffbfdb67a8c7f070f6e7a7be614729b2e350f9c7973d62e09ae7exeRedLineStealer
2021-03-11 20:22:156f9ca1a18eb9a5c5938a9a74a1072a44fbd16685172468e61c7a564a8175c9a7exeRedLineStealer
2021-03-10 22:14:1220d2a831d8c0d91df5a26a5c3251b82c31254185ec12bd4ff8fa305c2103235bexeRedLineStealer
2021-03-10 18:31:470a5a39d2e42746ac3c06bae3c5a95a9ef34062a4c629854737ff55286581f3d7exe RedLineStealer
2021-03-09 16:14:295d63d1c4eb964d27d53d83b399b38ffad6609b204b8741e5626d4427cc7421afexeRedLineStealer
2021-03-09 12:11:107ad0f14d763cfe8710a7bce6ccd3bb6589d059142d2662800f2b4f81e3cf2737exeRedLineStealer