URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rfddsdaajbs.fihsifuiiusuiuduf.com
Domain registrar:Webnic -
Domain registration date:2024-01-26 18:00:59 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-07-26 12:23:04 UTC
Total malware sites :36
Online malware sites :0 (0%)
Offline Malware sites :36 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-09-07 08:54:57 162.216.242.208parked.dynu.comNot listedAS398019 DYNU- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-26 12:30:14http://rfddsdaajbs.fihsifuiiusuiuduf.com/11Offlineencrypted NDA0E
2024-07-26 12:29:53http://rfddsdaajbs.fihsifuiiusuiuduf.com/c6Offlineencrypted NDA0E
2024-07-26 12:29:36http://rfddsdaajbs.fihsifuiiusuiuduf.com/aOfflineencrypted NDA0E
2024-07-26 12:29:34http://rfddsdaajbs.fihsifuiiusuiuduf.com/aaOfflineencrypted NDA0E
2024-07-26 12:29:30http://rfddsdaajbs.fihsifuiiusuiuduf.com/bOfflineencrypted NDA0E
2024-07-26 12:29:29http://rfddsdaajbs.fihsifuiiusuiuduf.com/111Offlineencrypted NDA0E
2024-07-26 12:29:23http://rfddsdaajbs.fihsifuiiusuiuduf.com/bbOfflineencrypted NDA0E
2024-07-26 12:29:21http://rfddsdaajbs.fihsifuiiusuiuduf.com/bbbOfflineencrypted NDA0E
2024-07-26 12:29:20http://rfddsdaajbs.fihsifuiiusuiuduf.com/cccOfflineencrypted NDA0E
2024-07-26 12:29:17http://rfddsdaajbs.fihsifuiiusuiuduf.com/ccOfflineencrypted NDA0E
2024-07-26 12:29:16http://rfddsdaajbs.fihsifuiiusuiuduf.com/cOfflineencrypted NDA0E
2024-07-26 12:29:13http://rfddsdaajbs.fihsifuiiusuiuduf.com/222Offlineencrypted NDA0E
2024-07-26 12:29:13http://rfddsdaajbs.fihsifuiiusuiuduf.com/33Offlineencrypted NDA0E
2024-07-26 12:27:05http://rfddsdaajbs.fihsifuiiusuiuduf.com/pp.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:59http://rfddsdaajbs.fihsifuiiusuiuduf.com/pei.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:40http://rfddsdaajbs.fihsifuiiusuiuduf.com/t2.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:39http://rfddsdaajbs.fihsifuiiusuiuduf.com/aaa.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:38http://rfddsdaajbs.fihsifuiiusuiuduf.com/peinf.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:36http://rfddsdaajbs.fihsifuiiusuiuduf.com/tpeinf...OfflineCoinMiner exe NDA0E
2024-07-26 12:26:35http://rfddsdaajbs.fihsifuiiusuiuduf.com/nxmr.exeOfflineCoinMiner exe NDA0E
2024-07-26 12:26:27http://rfddsdaajbs.fihsifuiiusuiuduf.com/tdrplo...Offlineexe phorpiex ext NDA0E
2024-07-26 12:26:23http://rfddsdaajbs.fihsifuiiusuiuduf.com/t1.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:20http://rfddsdaajbs.fihsifuiiusuiuduf.com/t.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:14http://rfddsdaajbs.fihsifuiiusuiuduf.com/1.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:26:09http://rfddsdaajbs.fihsifuiiusuiuduf.com/asec.exeOfflineexe NDA0E
2024-07-26 12:26:02http://rfddsdaajbs.fihsifuiiusuiuduf.com/o.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:25:53http://rfddsdaajbs.fihsifuiiusuiuduf.com/tt.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:25:12http://rfddsdaajbs.fihsifuiiusuiuduf.com/pi.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:59http://rfddsdaajbs.fihsifuiiusuiuduf.com/m.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:30http://rfddsdaajbs.fihsifuiiusuiuduf.com/a.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:30http://rfddsdaajbs.fihsifuiiusuiuduf.com/npp.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:21http://rfddsdaajbs.fihsifuiiusuiuduf.com/r.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:13http://rfddsdaajbs.fihsifuiiusuiuduf.com/twztl.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:13http://rfddsdaajbs.fihsifuiiusuiuduf.com/s.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:24:07http://rfddsdaajbs.fihsifuiiusuiuduf.com/11.exeOfflineexe phorpiex ext NDA0E
2024-07-26 12:23:09http://rfddsdaajbs.fihsifuiiusuiuduf.com/newtpp...Offlineexe phorpiex ext NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-09-01 08:04:24dc69f2b947673cdb4775a4ae081e009f6a713a35000e43e5fa86d5eabe99a7e4exe Phorpiex
2024-08-01 07:49:49d281e0a0f1e1073f2d290a7eb1f77bed4c210dbf83a0f4f4e22073f50faa843fexe Phorpiex
2024-07-31 05:25:424cb590dfafb7653379326e840d9b904a3cf05451999c4f9eb66c6e7116b68875exe Phorpiex
2024-07-27 20:42:36772ad3ca0bc4c88bd4042562e8fefb34fe52a1f709622d819f806770e582541bexePhorpiex
2024-07-26 12:30:142ebc4a92f4fdc27d4ab56e57058575a8b18adb076cbd30feea2ecdc8b7fcd41funknown  
2024-07-26 12:29:53f8706ef31b6df9c8c0accc593a9c73521e6c66e95610f7f9032798637cb5695aunknown  
2024-07-26 12:29:36985da56fb594bf65d8bb993e8e37cd6e78535da6c834945068040faf67e91e7dunknown  
2024-07-26 12:29:33985da56fb594bf65d8bb993e8e37cd6e78535da6c834945068040faf67e91e7dunknown  
2024-07-26 12:29:303c692532b72c68c1cd92374fc28b54afd0b27db1eabd7785c6a0e5b1e92b59c9unknown  
2024-07-26 12:29:29985da56fb594bf65d8bb993e8e37cd6e78535da6c834945068040faf67e91e7dunknown  
2024-07-26 12:29:232ebc4a92f4fdc27d4ab56e57058575a8b18adb076cbd30feea2ecdc8b7fcd41funknown  
2024-07-26 12:29:212ebc4a92f4fdc27d4ab56e57058575a8b18adb076cbd30feea2ecdc8b7fcd41funknown  
2024-07-26 12:29:203c692532b72c68c1cd92374fc28b54afd0b27db1eabd7785c6a0e5b1e92b59c9unknown  
2024-07-26 12:29:173c692532b72c68c1cd92374fc28b54afd0b27db1eabd7785c6a0e5b1e92b59c9unknown  
2024-07-26 12:29:16985da56fb594bf65d8bb993e8e37cd6e78535da6c834945068040faf67e91e7dunknown  
2024-07-26 12:29:133c692532b72c68c1cd92374fc28b54afd0b27db1eabd7785c6a0e5b1e92b59c9unknown  
2024-07-26 12:29:132ebc4a92f4fdc27d4ab56e57058575a8b18adb076cbd30feea2ecdc8b7fcd41funknown  
2024-07-26 12:27:04a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:26:58feb4c3ae4566f0acbb9e0f55417b61fefd89dc50a4e684df780813fb01d61278exe Phorpiex
2024-07-26 12:26:39e972fb08a4dcde8d09372f78fe67ba283618288432cdb7d33015fc80613cb408exePhorpiex
2024-07-26 12:26:39a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:26:376c19c61dd69a8628e38246fc2ce05cee66967eb36f49bde4797892f441b10cadexe Phorpiex
2024-07-26 12:26:36d93add71a451ec7c04c99185ae669e59fb866eb38f463e9425044981ed1bcae0exe CoinMiner
2024-07-26 12:26:35dd12cb27b3867341bf6ca48715756500d3ec56c19b21bb1c1290806aa74cb493exeCoinMiner
2024-07-26 12:26:27a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:26:23a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:26:20d8b83f78ed905a7948e2e1e371f0f905bcaaabbb314c692fee408a454f8338a3exePhorpiex
2024-07-26 12:26:13d8b83f78ed905a7948e2e1e371f0f905bcaaabbb314c692fee408a454f8338a3exePhorpiex
2024-07-26 12:26:089a53a95b0c1288c8e723030c47029455cb2c15ab69732f2a9fc2aad6b418a200exe  
2024-07-26 12:26:01a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:25:52a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:25:113f16f4550826076b2c8cd7b392ee649aeb06740328658a2d30c3d2002c6b7879exe Phorpiex
2024-07-26 12:24:57a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:24:30feb4c3ae4566f0acbb9e0f55417b61fefd89dc50a4e684df780813fb01d61278exe Phorpiex
2024-07-26 12:24:30a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:24:20a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:24:13a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:24:13a992920e64a64763f3dd8c2a431a0f5e56e5b3782a1496de92bc80ee71cca5baexe Phorpiex
2024-07-26 12:24:07d8b83f78ed905a7948e2e1e371f0f905bcaaabbb314c692fee408a454f8338a3exePhorpiex
2024-07-26 12:23:08d8b83f78ed905a7948e2e1e371f0f905bcaaabbb314c692fee408a454f8338a3exePhorpiex