URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sndyunitedkesokosnkh.dns.army
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-26 07:09:02 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-26 07:09:06 103.141.138.132Not listedAS135905 VNPT-AS-VN- VNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-26 07:09:06http://sndyunitedkesokosnkh.dns.army/chnsfrnd1/...Offlineexe Loki ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-27 06:48:408b074dd94b8fc1a3e44ca2b59c1b7544db56290b95167dc8fde80d5c25e5f785exeLoki
2021-01-27 06:34:49af59a0212b97aec8f20b1e156ebf3bf276635f434fff2e869b8ba84d1d75b0f6exeLoki
2021-01-27 01:19:388bcaa843a3dbd507050d15f193571dfc2a1e584e23a6dea41431067b188ea199exeLoki
2021-01-26 07:47:283f1bb5d6ba0c98f35a9274f5f682185d52102d207b1525060d6696142b2d1634exeLoki
2021-01-26 07:09:060f7b923e9903586f3b7ffd347ce3ea71cd31b89559d9c9929cde084c54cc2c0bexeLoki