URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rmp.skswebsites.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-20 11:40:16 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-20 13:27:01 166.62.28.9797.28.62.166.host.secureserver.netNot listedAS26496 AS-26496-GO-DADDY-COM-LLC- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-20 13:27:01http://rmp.skswebsites.com/zfkdoc.rarOfflinedll Dridex ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-21 14:34:0165670647bfb1466e6089b3aa04f67e4c83575789e7f7dac6f4747c0efdba8d1edll Dridex
2021-01-21 13:26:4888a3bb6431cc7f057dfcef20822259fa0a95004a081dc94e64e6a8ae19829c8edll Dridex
2021-01-21 09:46:3931c6759d37f3ed690b2bb1daf76b2adf643a1e7f120332759231818f41e8a3c3dll Dridex
2021-01-21 08:14:4690bd41b029a4618b84125ea9b16256f07d8a29ca4a11e6a902bbe336c2386f52dll Dridex
2021-01-21 02:20:20fcddcf6dedd8f2bd69e1007831e397e243d4994bfe6d90b5840c1cf91eacf245dllDridex
2021-01-20 21:06:353459d30b5d2e6c58ddb8dcd9f45f5141f8d15c55fff16f9cc76ec621e6d829fbdll Dridex
2021-01-20 20:10:082bfa88a5c855f4d24139d5d9c556cfbdb05a5a68b23a528ae53226d526dc4e7dexeDridex
2021-01-20 19:12:05b553789ab78bdf72ecaec67917b7fabbcd485bbd2d1b1baa03802cf01147927ddll Dridex
2021-01-20 18:34:437872f401516f88967a064039f38f20de144e76dcc3a5a26413312dff29041e26dll Dridex
2021-01-20 17:56:54f7c8f98516cab79befde56567a6c5023ffb9e096ebff140d96dcf6e77583d9b9dll Dridex
2021-01-20 17:21:33d160b47e8ef2f76e25caee95595893d3f55986de9216ee247e7e48fcb90edf99dll Dridex
2021-01-20 16:30:54e4191288a595ba5a8af0d6bf081d0963fbeb553c0667a343c7d217f2b65ddf4bdll Dridex
2021-01-20 16:05:289cdc32b5cd2fb375072d681b488fe5b40789e2c87d36044033579b0281ee35f6dll Dridex
2021-01-20 14:12:27791252fc4def3c4c3bdb270633ffc88c0e2cd8e8e8ba299825a83841a273e7dddllDridex
2021-01-20 13:27:01b9bb671587f2dad8a3df83d6bd0b7b8327edf93fadbefe8b6aa7eabe6698ae88dllDridex