URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: short.extrafandome.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-23 23:33:05 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-05-27 05:30:32 99.83.154.118a51062ecadbb5a26e.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-06-23 23:33:08 195.181.169.92unn-169-181-195-92.datapacket.comNot listedAS60068 CDN77- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-24 05:11:04http://short.extrafandome.com/p6-2.exeOffline32 cryptbot exe RaccoonStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-14 19:44:578b9455340782df54173b872faf9c27da68d16667ac40397dfa2ae8221766520bexe Downloader.Upatre
2021-09-18 09:21:34601c45de707f7993a9101ac0f9eca21bf3e0865cf5cb952272c76975ad05a2b8exe Downloader.Upatre
2021-07-21 05:26:3988a2e91597137f9a64ccf66c89390c533d1a85d09f8310b658f73bf6ad45db2aexeCryptBot
2021-07-20 11:29:43ae4ccd912a3f2ad87789956660ee5485bb5fcd0f36c1d0d4f1272e3ae1f668f3exeCryptBot
2021-07-19 17:55:11f2046a05e0d3e80544ef276bfc96ad1dd92ced0f97d32c7e7825f9d558ad2b10exe Cryptbot
2021-07-19 05:34:46ffe5b10cd81f4c1484f62863be69ea28732b8e765b12569c5cd11b463bd4d261exeCryptbot
2021-07-18 18:03:28d0c2ffb2664b0757fa896299577579cb6bd7a7e9dd601e11c13efcc7b5879e2dexeCryptbot
2021-07-18 05:43:533d3bd7e7f5fabaf2510cf58eb74a9474b44c5d1389538ee7a93826a25531bd56exeCryptBot
2021-07-17 06:02:25b3a99ecc4ab9f73d814f0f64a3aa0c71ee3cf94872f2f8ca3a2a1c5d630c095dexeCryptBot
2021-07-17 05:35:133d364150c09d1f0c4a9eab0144fb4754bdcfa96ad1d0bd874308e625c5958b75exeCryptbot
2021-07-16 17:48:519cbdf7f433f59f69ed01b5d6928259ad816d83c3680b8d14bbc54f2e8cd7b752exe 
2021-07-16 05:26:111a70a7de8a393638b80336e9d2b225c2fd199d9d3eed3ad2c007656cc20c2b4aexeCryptbot
2021-07-15 18:09:510dbfcf05490597b25cd7e6abaf698d821b00301625a85b3f1ee8e75d8a090a49exeCryptbot
2021-07-15 06:00:41349fcfd6f24473d8b0c9429c0f71459a178125b6d42a48129d357ce99eca94feexeCryptBot
2021-07-14 22:23:0054f791796231f7899d753f0ba44e7387bf7748dc7a28adbd28f2067c9ab88605exeCryptbot
2021-07-14 13:16:314fed7b4a593e61c9f6b4d0003320bb985cc2be10164bc43aa47e39013b920538exe RaccoonStealer
2021-06-24 05:11:0406cf7c7c1a2d8f8647c977803466fd5b3a39dded0312fb23575eeacfaeaf07d6exeCryptBot