URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rmdwk19obfzrq03ohby.xyz
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-03-19 14:23:03 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-19 14:23:05 35.228.48.2727.48.228.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- FIno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-03-19 14:23:05http://rmdwk19obfzrq03ohby.xyz/apple.gifOfflineb-TDS dll geofenced IcedID ext ITA SilentBuilder TR Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-03-24 18:20:245c42708a789f6332aadfb2caf0672aaaf36a3f31240088f45beafddd2006cec1dll IcedID
2021-03-23 19:59:47b4f0854c50210cd264a53bba4df0f5f889d21aeb2a929cf4589c2ce085335b72dll IcedID
2021-03-23 12:00:27aebd18e94583e79dc6b11bb4b993d13d414d3dc0d2d4e9105d1dd3d8d0addd13dll IcedID
2021-03-22 12:01:567b0290fdb87e425a869defb681c5fbbed330a000c0cdb6e8c9c52b0e8b1b5492dllIcedID
2021-03-19 14:28:2441b9863c45245876aab05824d58c2a130871f806085db4d9311f857cabab1667dllIcedID