URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | quttnerttatert.com |
|---|---|
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Not blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2020-06-24 07:39:11 UTC |
| Total malware sites : | 5 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 5 (100%) |
| A record(s) observed : | 3 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2020-07-27 16:12:55 | 103.26.204.161 | Not listed | AS132335 LEAPSWITCH-IN-AS-AP | IN | no | |
| 2020-06-28 12:21:20 | 52.59.94.5 | ec2-52-59-94-5.eu-central-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | DE | no |
| 2020-06-24 07:39:13 | 162.241.69.94 | server.shettysudhir.com | Not listed | AS19871 NETWORK-SOLUTIONS-HOSTING | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-06-25 13:04:34 | http://quttnerttatert.com/SvS/8704510.msi | Offline | msi Pony | |
| 2020-06-24 20:30:35 | http://quttnerttatert.com/CvC/60144702.jpg | Offline | exe Loki | |
| 2020-06-24 20:16:11 | http://quttnerttatert.com/CvC/130258774.jpg | Offline | exe Loki | |
| 2020-06-24 20:05:34 | http://quttnerttatert.com/CvC/10376850.jpg | Offline | AgentTesla | |
| 2020-06-24 07:39:13 | http://quttnerttatert.com/CvC/63496900.jpg | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-06-25 13:04:34 | b2d579828599ae4e265f77899466dc005e7685b50dcbf6817388ea22d404ab2c | msi | Pony | |
| 2020-06-24 20:30:35 | 3ed18d9a941c285eb6ff1b78fe9628a75cb8ec0326d993be7c848db4825c5fff | exe | Loki | |
| 2020-06-24 20:16:11 | 2e30eeb0f5c5bf1f8d8b467261de4a0c5a55841e12cb1bb3c996f58b170cc492 | exe | Loki | |
| 2020-06-24 20:05:34 | d749f756093b6a3ee4d5265ea6f9e82aa517c754487fcbebb7a748324cbcd10e | exe | AgentTesla | |
| 2020-06-24 07:39:13 | f5d8421d1d7a5e9b309394d36796a05e1ae22f64d642d2a30b69202aaf9bb262 | exe | AgentTesla |
IN
DE
US