URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sentineob.sbs
Domain registrar:Webnic -
Domain registration date:2025-11-18 15:50:54 UTC
Abuse complaint sent to registrar: Yes (2025-11-18 18:47:01 UTC to compliance_abuse{at}webnic[dot]cc)
Domain registry:Special Broadcasting Service -
Abuse complaint sent to registry: Yes (2025-11-18 18:47:01 UTC to ngtld-sbs{at}cscinfo[dot]com)
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-11-18 18:43:05 UTC
Total malware sites :5
Online malware sites :4 (80%)
Offline Malware sites :1 (20%)
Newest active malware site :2025-11-19 14:48:09 UTC
Oldest active malware site :2025-11-18 18:43:07 UTC (Age: 20 hours, 20 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-18 18:43:07 185.100.157.69Not listedAS215826 Partner-Hosting-LTD- SEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-19 14:48:09https://sentineob.sbs/qwe.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter
2025-11-19 14:08:08https://sentineob.sbs/program.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter
2025-11-19 14:08:08https://sentineob.sbs/build.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter
2025-11-19 07:52:06https://sentineob.sbs/test1.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2025-11-18 18:43:07https://sentineob.sbs/test.exeOnlinec2-monitor-auto dropped-by-amadey c2hunter

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-19 14:48:09ae89095b97719ff3ce49ac533b9b91fee0025d20e67c7ef2d50269328474f370exe  
2025-11-19 14:08:0884e07e93ea30913d09dd30168737fd95d2ee45253b74ced5ac6eb661930d1e0eexe  
2025-11-19 14:08:087139bd889d0406d0135e246cb9dc5554bfd4377a93990f5e458de88a167ee5c8exe  
2025-11-19 09:27:35ea616668e49c375ce476a0d12848b6b464387cc7557c2e3c5c652ed07faf4b70exe 
2025-11-18 18:43:07be6590248048cc5aee1b416855a88ff4cfbc30697b79aa8f35b94e3d79ab6276exe