URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: skinnybean.org
Domain registrar:NameSilo -
Domain registration date:2019-05-13 12:05:02 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-05-27 08:23:18 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-27 08:23:20 131.153.37.3svr157.fastwebhost.comNot listedAS20454 SSASN2- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-10 10:47:07https://skinnybean.org/wp-admin/js/z3T.exeOfflineexe Formbook ext abuse_ch
2022-02-08 08:29:07https://skinnybean.org/T10/chi.exeOfflineexe Formbook ext opendir abuse_ch
2022-01-18 16:03:08https://skinnybean.org/k9/57t.exeOfflineAgentTesla ext exe abuse_ch
2020-05-27 08:23:20http://skinnybean.org//wp-admin/a1/007_WiwDCbZM...Offlineencrypted GuLoader ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-10 10:47:07a94cf69dea9775df9f51f32d9591f7208ac9c712289a1b851c30de3938b5a976exeFormbook
2022-02-08 08:29:07f61f02c5be2ef5988f474ffc148b099942ab8582cd4aac8b3c991436f6230592exeFormbook
2022-01-18 16:03:08ea67a0c13e555280f7a4a10c8000f02fdc408436b7b41a5a9cfad4034510414bexeAgentTesla
2020-05-27 08:23:20deafb49f00c8fe75605a619f054fa62cd1862b99149117894d596bfb26d97fdeunknown