URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: s3.rokket.space
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-20 21:26:18 UTC
Total malware sites :15
Online malware sites :0 (0%)
Offline Malware sites :15 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 08:50:46 51.254.199.13mail.relaay.meNot listedAS16276 OVH- FRyes
2020-09-22 19:00:37 5.9.14.17f144.forex-box.comNot listedAS24940 HETZNER-AS- DEno
2020-08-20 21:26:19 46.4.97.19static.19.97.4.46.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-31 16:45:04https://s3.rokket.space/t_zKMm47.jpgOfflineAgentTesla ext exe zbetcheckin
2020-08-31 14:49:06https://s3.rokket.space/t_QBMrlH.jpgOfflineAgentTesla ext exe zbetcheckin
2020-08-31 14:49:04https://s3.rokket.space/t_uI9jyG.jpgOfflineAgentTesla ext exe zbetcheckin
2020-08-31 13:00:10https://s3.rokket.space/t_X6V9JC.txtOfflineAgentTesla ext exe abuse_ch
2020-08-31 09:13:34https://s3.rokket.space/t_oUfbGz.txtOfflineexe Formbook ext abuse_ch
2020-08-31 06:34:19https://s3.rokket.space/t_6OuAvd.txtOfflineAgentTesla ext exe abuse_ch
2020-08-31 05:45:35https://s3.rokket.space/t_bU3cLG.txtOfflineexe Loki ext abuse_ch
2020-08-26 16:54:18https://s3.rokket.space/t_BP2FjE.txtOfflineAgentTesla ext Anonymous
2020-08-26 16:54:15https://s3.rokket.space/t_fr7OUh.txtOfflineNanoCore ext Anonymous
2020-08-26 16:54:12https://s3.rokket.space/t_xFfMJD.txtOfflineAgentTesla ext Anonymous
2020-08-26 16:54:07https://s3.rokket.space/t_7axmFl.txtOfflineAgentTesla ext Anonymous
2020-08-26 16:54:04https://s3.rokket.space/t_M2ZpAo.txtOfflineAgentTesla ext Anonymous
2020-08-26 16:53:08https://s3.rokket.space/t_mPOrbg.txtOfflineAgentTesla ext Anonymous
2020-08-26 11:31:23https://s3.rokket.space/t_GLWxqZ.txtOfflineLoki ext Anonymous
2020-08-20 21:26:19https://s3.rokket.space/t_pLg4Ox.txtOfflineAgentTesla ext James_inthe_box

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-31 16:45:04a0d03802ed408345b7d80137600b60ee7c1b84591ac18e61ec94c959a75f6508exe AgentTesla
2020-08-31 14:49:0660d5cc58c4a1f7e3841979da2fd713378e90c054194a9f4b30735a671647fc38exeAgentTesla
2020-08-31 14:49:04cd80340bee608d8a8b27a5e2ac7f0b2dfdf319cdd285d9acd9c462f6983dbf4bexeAgentTesla
2020-08-31 13:00:104eff27126b74a235694015e24eef51535df0957aee93773e67db901b07df3270exeAgentTesla
2020-08-31 09:13:3460dac53124b3a9155d09cad5c886eb32ff5a5bea1329b527dcf5eb7cf93a3f74exeFormbook
2020-08-31 06:34:19e639997f6ee7e96b1356622bc3f5449e8ce3aeb46100e775875cc41cc891d587exeAgentTesla
2020-08-31 05:45:3510070ec7d3520c0f11223b9602b0d78c066eaa6b56193385d39346838669c50aexeLoki
2020-08-26 16:54:187f258d40028c77692ea89ce40261674a93143edf9d8c03ec8e8270344f945f1eexeAgentTesla
2020-08-26 16:54:15dc60cbd5aea9991eae966cb8499ff91647ca4c2f4a9005c17e7b804fce1bafb6exeNanoCore
2020-08-26 16:54:12973493f3261373ffb49c58eaafb07235026ade4c29fc6e925f7d742953ce763cexeAgentTesla
2020-08-26 16:54:07f50427b5ec3b2976eaa227bed22b72f732208dceae47d073d89243590235a62dexeAgentTesla
2020-08-26 16:54:04a02d9a1d5053065855293ee57d8a4ec5a8d6805d3290f0f80f3e60ceccef2b0fexeAgentTesla
2020-08-26 16:53:08b023a34548a0f58904fab9d0c977edd8eef12a8185661dcb51b9937df768aed1exeAgentTesla
2020-08-26 11:31:2359f1b5bead17f4c71561f6092f4b03135b152a0f4a32b8c21c008b4ee7f46995exeLoki
2020-08-20 21:26:19bc115dc2be13d9053e04bcac9c102a26391d7c76134d9364cddb798e800949f7exeAgentTesla