URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sostener2024dns.duckdns.org
Domain registrar:Gandi -
Domain registration date:2013-04-12 19:58:56 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-04-12 18:48:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :60

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-24 22:12:43 192.169.69.26sinkhole.hyas.comNot listedAS27323 SERVERSTADIUM- USno
2025-07-24 10:18:59 178.73.218.5c-178-73-218-5.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-06-14 18:49:59 46.246.6.4c-46-246-6-4.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-23 22:18:24 178.73.192.11c-178-73-192-11.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-23 17:34:13 46.246.86.23c-46-246-86-23.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-23 11:08:43 46.246.86.22c-46-246-86-22.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-22 23:33:33 46.246.84.11c-46-246-84-11.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-05-23 12:07:18 46.246.6.5c-46-246-6-5.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-18 05:24:31 46.246.4.17c-46-246-4-17.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno
2025-07-16 23:43:10 46.246.6.12c-46-246-6-12.ip4.frootvpn.comNot listedAS42708 GLESYS- SEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-12 18:48:26http://sostener2024dns.duckdns.org/sostener.vbsOfflineopendir RemcosRAT ext ua-wget vbs xworm DaveLikesMalwre
2025-04-12 18:48:10http://sostener2024dns.duckdns.org/incrustado.vbsOfflinenjRAT ext opendir ua-wget vbs DaveLikesMalwre