URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: srv43923540.ultasrv.com
Domain registrar:Public Domain Registry -
Domain registration date:2022-03-29 21:31:01 UTC
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-07-11 08:11:03 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-08-08 14:30:09 194.195.211.26194-195-211-26.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2022-07-11 08:11:04 79.133.56.159Not listedAS214036 ULTAHOST-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-12 08:28:04http://srv43923540.ultasrv.com/bZSQH.exeOfflineAgentTesla ext exe abuse_ch
2022-07-12 06:57:04http://srv43923540.ultasrv.com/EmMGF.exeOffline32 a310Logger ext exe zbetcheckin
2022-07-12 02:16:04http://srv43923540.ultasrv.com/tELGR.exeOffline32 AsyncRAT ext exe zbetcheckin
2022-07-12 02:16:04http://srv43923540.ultasrv.com/RwXaE.exeOffline32 AveMariaRAT ext exe zbetcheckin
2022-07-12 02:15:05http://srv43923540.ultasrv.com/HgNcZ.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-07-12 02:01:04http://srv43923540.ultasrv.com/zECRo.exeOffline32 BluStealer exe zbetcheckin
2022-07-11 20:11:04http://srv43923540.ultasrv.com/yTQCE.exeOffline32 exe zbetcheckin
2022-07-11 19:38:04http://srv43923540.ultasrv.com/JmQgT.exeOffline32 AsyncRAT ext exe zbetcheckin
2022-07-11 14:28:04http://srv43923540.ultasrv.com/ArCQG.exeOffline32 AveMariaRAT ext exe zbetcheckin
2022-07-11 14:27:03http://srv43923540.ultasrv.com/gRMQK.exeOfflineexe SnakeKeylogger ext abuse_ch
2022-07-11 14:26:04http://srv43923540.ultasrv.com/EjFML.exeOfflineexe MassLogger ext abuse_ch
2022-07-11 14:05:05http://srv43923540.ultasrv.com/bFPTx.exeOffline32 exe QuasarRAT ext zbetcheckin
2022-07-11 13:53:05http://srv43923540.ultasrv.com/CjNaT.exeOffline32 AZORult ext exe zbetcheckin
2022-07-11 13:53:05http://srv43923540.ultasrv.com/bFCRH.exeOffline32 exe Formbook ext zbetcheckin
2022-07-11 11:28:03http://srv43923540.ultasrv.com/gSGYs.exeOfflineexe SnakeKeylogger ext vxvault
2022-07-11 09:12:04http://srv43923540.ultasrv.com/ZzYaQ.exeOffline32 exe NanoCore ext RedLineStealer ext zbetcheckin
2022-07-11 09:12:04http://srv43923540.ultasrv.com/SoCJQ.exeOffline32 exe Formbook ext zbetcheckin
2022-07-11 09:12:04http://srv43923540.ultasrv.com/sSEDt.exeOffline32 AsyncRAT ext exe zbetcheckin
2022-07-11 08:20:05http://srv43923540.ultasrv.com/JxRQX.exeOfflineAsyncRAT ext exe abuse_ch
2022-07-11 08:14:04http://srv43923540.ultasrv.com/oFNTE.exeOfflinea310Logger ext exe abuse_ch
2022-07-11 08:13:14http://srv43923540.ultasrv.com/cFRPD.exeOfflineexe RedLineStealer ext abuse_ch
2022-07-11 08:11:04http://srv43923540.ultasrv.com/BcJRF.exeOfflineAveMariaRAT ext exe SnakeKeylogger ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-12 08:28:049051b379d7ee2fb0ade18042ddf9d779523991df4a3bd3ddbf7ddcf35b7555c0exeAgentTesla
2022-07-12 06:57:04658142bdeec19fb3ff0556a38a592458b7f005f69d11a39c34d67fd9efe6222cexea310Logger
2022-07-12 02:16:04228bebac2f9018b5ad2cfce26ee6360488f42011469ba1ced90830eb5e01c3e5exeAsyncRAT
2022-07-12 02:16:04c94f8f04a2c0697a50e52b396b411491a88f1b0ba5bbd07f36fcf07f3a4daf7eexeAveMariaRAT
2022-07-12 02:15:05bfba4ae9711fe2e18e5906f66c4bffee48b14ef5a6e522fa874b373a9be2d834exeRemcosRAT
2022-07-12 02:01:049b83c1efc74833172375826612ca54ccf601b3b2bf24dab96b63da8a41dfbeb8exeBluStealer
2022-07-12 00:48:38c94f8f04a2c0697a50e52b396b411491a88f1b0ba5bbd07f36fcf07f3a4daf7eexeAveMariaRAT
2022-07-11 20:11:04a8765a153ef00386ec1c44fd75367f2ac7da5e360fee0d21ec4156e3673cec09exe 
2022-07-11 19:38:049f340084a105595091444c4fe491dcb4cee297c296812165dcbe4f23579fff1aexeAsyncRAT
2022-07-11 15:43:455853f53461d961ec48b75c4a0a24c6de33bcc4e3fb8a3bd390492810290fcfc8exe QuasarRAT
2022-07-11 14:55:2874e00831d912f1480b7ded456de61560adab920f54d88cbe6f9f061f52e72336exeNanoCore
2022-07-11 14:28:040c78222c8ba928915a4daa3332b2bf6129e243676c9de511332e95caa14c573dexeAveMariaRAT
2022-07-11 14:27:0362571913b75605bf3ebd0b6958f6866aab99123fdc974d3488bf2a34ca2361f8exeSnakeKeylogger
2022-07-11 14:26:04ccde07037915b9b7f5e4ffa10d4cc1d2d8473284fce212d673c44e9fc79e6171exeMassLogger
2022-07-11 14:05:047b3eadf17f45d36e0b790b6a18cc115df9e6419b2dd5703f5e2dced29e9095adexe 
2022-07-11 13:53:05cd3930292301311b4a3893cad7875fbb9841cb7a903fbd9a2ca8b560e4e8a810exeAZORult
2022-07-11 13:53:04ed7cffa33cba2ae44d44f61137d598743a1e9a3c20a66d5a77381e39846ad3beexeFormbook
2022-07-11 11:28:03bceecd93ab69c547f69531c9e81c8d7aa08885096a9e40b80c575b378bf0bcbbexeSnakeKeylogger
2022-07-11 09:12:042139f03c25f75f5cd494f3b74cd3a9f5b8eefc26b4982ff95d7602c5b608c2eeexeRedLineStealer
2022-07-11 09:12:04ed7cffa33cba2ae44d44f61137d598743a1e9a3c20a66d5a77381e39846ad3beexeFormbook
2022-07-11 09:12:04104ce6238e3110804de201906d968f3b95fd6e8bc6018002764eda7e60c57fd4exeAsyncRAT
2022-07-11 08:20:05104ce6238e3110804de201906d968f3b95fd6e8bc6018002764eda7e60c57fd4exeAsyncRAT
2022-07-11 08:14:04658142bdeec19fb3ff0556a38a592458b7f005f69d11a39c34d67fd9efe6222cexea310Logger
2022-07-11 08:13:14e9d0051a518d260fa503b82b6d4be8535a0bad93f2e69b2b75a6f78e44a7eb82exeRedLineStealer
2022-07-11 08:11:0362571913b75605bf3ebd0b6958f6866aab99123fdc974d3488bf2a34ca2361f8exeSnakeKeylogger