URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | resourceedge.org |
|---|---|
| Domain registrar: | Domain.com ![]() |
| Domain registration date: | 2009-09-15 14:12:05 UTC |
| Abuse complaint sent?: | Yes (2023-07-22 18:50:02 UTC to ops{at}pir[dot]org) |
| Spamhaus DBL : | Abused domain (malware) |
| SURBL : | Blocked |
| Quad9 : | Blocked |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2023-07-06 11:08:03 UTC |
| Total malware sites : | 2 |
| Online malware sites : | 1 (50%) |
| Offline Malware sites : | 1 (50%) |
| Newest active malware site : | 2023-07-22 18:49:08 UTC |
| Oldest active malware site : | 2023-07-22 18:49:08 UTC (Age: 2 years, 4 months, 21 days, 22 hours, 51 minutes) |
| A record(s) observed : | 2 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-01-05 16:59:55 | 41.80.37.28 | host05.safaricombusiness.co.ke | Not listed | AS37061 Safaricom | KE | yes |
| 2023-07-06 11:09:07 | 197.248.5.10 | host05.safaricombusiness.co.ke | Not listed | AS37061 Safaricom | KE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-07-22 18:49:08 | https://resourceedge.org/new.exe | Online | dropped-by-PrivateLoader Lumma LummaStealer | |
| 2023-07-06 11:09:07 | https://resourceedge.org/p.ps1 | Offline | dropped-by-amadey |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-01-25 16:29:19 | 05241f83ecb3059e77a5442b3a57da2c92a76aab59dcbf7479c47d43eed08d4c | exe | ||
| 2023-07-22 18:49:08 | d9f6408b67628d5618a4fbaba97404ac55988633ccb2a02a09c95b0b134bafc9 | exe | LummaStealer |

KE