URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sharenvpn.net
Domain registrar:Webnic -
Domain registration date:2025-05-26 09:36:34 UTC
Abuse complaint sent to registrar: Yes (2025-06-03 06:51:01 UTC to compliance_abuse{at}webnic[dot]cc)
Domain registry:VeriSign Global Registry Services -
Abuse complaint sent to registry: Yes (2025-06-03 06:51:01 UTC to info{at}verisign-grs[dot]com)
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-06-03 06:47:03 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-03 06:47:08 104.21.112.1Not listedAS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.16.1Not listedAS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.32.1Not listedAS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.48.1Not listedAS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.64.1Not listedAS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.80.1SBL681411AS13335 CLOUDFLARENETn/ano
2025-06-03 06:47:08 104.21.96.1Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-06-03 06:55:06https://sharenvpn.net/8888.exeOfflineexe LummaStealer abuse_ch
2025-06-03 06:54:06https://sharenvpn.net/GenomeBumper.exeOfflineexe LummaStealer abuse_ch
2025-06-03 06:53:08https://sharenvpn.net/uv.mp4OfflineLummaStealer abuse_ch
2025-06-03 06:52:07https://sharenvpn.net/uww.mp4OfflineLummaStealer abuse_ch
2025-06-03 06:47:09https://sharenvpn.net/ExtKm.exeOfflineexe Vidar ext abuse_ch
2025-06-03 06:47:08https://sharenvpn.net/svpn.mp4Offlinehta Vidar ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-03 06:55:060706072643eb149890c0a839b37664923328022f053e9eab500472b162efd54eexeLummaStealer
2025-06-03 06:54:0516b636cd08700aec2b34d586b7c34afe660a6de44507f12ab99e7bf21bead218exe LummaStealer
2025-06-03 06:53:0839ada6576268aa724ab7ac67e53055824d35304b627f5ccb8b8e5c271293b918unknown  
2025-06-03 06:52:07af9aa6f84e110d1eb9b5a42175ad0736425c87600cbc4cab93d8e18de0598a9aunknown  
2025-06-03 06:47:0998f49160a46ef3976ec83c7a2cddeae134cddfbe4f3ca00ebc0e5da7374b9953exeVidar
2025-06-03 06:47:08d59a277d5c9003a48eeae367ca9168f353510d9ec5f559e19997649adc536e66unknown