URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: srv60340528.ultasrv.com
Domain registrar:Public Domain Registry -
Domain registration date:2022-03-29 21:31:01 UTC
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-06-22 21:24:04 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-06-22 21:25:05 212.224.86.32Not listedAS214036 ULTAHOST-AS- DEno
2022-08-08 11:23:50 194.195.211.26194-195-211-26.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-06-23 09:40:05https://srv60340528.ultasrv.com/wHTEp.exeOffline32 exe Formbook ext zbetcheckin
2022-06-23 05:27:03https://srv60340528.ultasrv.com/pRJXn.exeOffline32 exe NanoCore ext zbetcheckin
2022-06-23 01:36:04https://srv60340528.ultasrv.com/QeKkR.exeOffline32 exe MassLogger ext zbetcheckin
2022-06-22 22:26:04https://srv60340528.ultasrv.com/ZmFSA.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-22 21:45:16https://srv60340528.ultasrv.com/NnMbE.exeOffline32 exe MassLogger ext zbetcheckin
2022-06-22 21:45:16https://srv60340528.ultasrv.com/gZNYa.exeOffline32 exe MassLogger ext zbetcheckin
2022-06-22 21:45:06https://srv60340528.ultasrv.com/yZXSx.exeOffline32 exe Formbook ext zbetcheckin
2022-06-22 21:45:06https://srv60340528.ultasrv.com/eYRQC.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-22 21:45:06https://srv60340528.ultasrv.com/LkDXC.exeOffline32 exe Formbook ext zbetcheckin
2022-06-22 21:45:06https://srv60340528.ultasrv.com/DcKqE.exeOffline32 exe zbetcheckin
2022-06-22 21:44:04https://srv60340528.ultasrv.com/ZzYaQ.exeOffline32 AgentTesla ext exe zbetcheckin
2022-06-22 21:44:04https://srv60340528.ultasrv.com/pZFGG.exeOffline32 exe MassLogger ext zbetcheckin
2022-06-22 21:44:04https://srv60340528.ultasrv.com/tHPMe.exeOffline32 exe RedLineStealer ext zbetcheckin
2022-06-22 21:32:15https://srv60340528.ultasrv.com/oNLCS.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-06-22 21:31:08https://srv60340528.ultasrv.com/YwYyZ.exeOffline32 exe Formbook ext zbetcheckin
2022-06-22 21:31:04https://srv60340528.ultasrv.com/DcGtJ.exeOffline32 exe MassLogger ext zbetcheckin
2022-06-22 21:25:05https://srv60340528.ultasrv.com/zKAMG.exeOffline32 AgentTesla ext exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-06-23 09:40:050e5c9966da705047c1eb5108fd658f512adafe31f93e625b0e2c00f13999c6afexeFormbook
2022-06-23 05:27:030c3d7e5bdb68d15bb1eeee00f9f80d0271ce6b8350be9e555464a1fb40b3157cexeNanoCore
2022-06-23 01:36:04b3e0001155a1a947e04c0d79405a6dc77325360751b7a2b101e566b377011a6fexeMassLogger
2022-06-22 22:26:0432b3c504aef4844c3e923b5b9aa211fb5e809db4f422d193b163ee726aabdc6eexeAgentTesla
2022-06-22 21:45:16b3e0001155a1a947e04c0d79405a6dc77325360751b7a2b101e566b377011a6fexeMassLogger
2022-06-22 21:45:16b3e0001155a1a947e04c0d79405a6dc77325360751b7a2b101e566b377011a6fexeMassLogger
2022-06-22 21:45:06dea0cc16bc8679d463362e3aaa4de18204f39eb21e5ff4a63dcc0f4be0f3e489exeAgentTesla
2022-06-22 21:45:06c4e5621522c13daa2e14625d2959d36d710acab153b083c35beca5135c15331eexeFormbook
2022-06-22 21:45:051b2718dd6066d8a211e942baba3df7341e615675088ff9b6496eb5901f50bf12exeFormbook
2022-06-22 21:45:0567016c9188ff460f924e0f096fc77a51f6e3a77e13e8757a95ef3affec0d3e5dexe 
2022-06-22 21:44:04b2b7f4f81651be65ab77882d7e4304d798d2d8d96889e7318e7692ba0c26b1c5exeAgentTesla
2022-06-22 21:44:04b3e0001155a1a947e04c0d79405a6dc77325360751b7a2b101e566b377011a6fexeMassLogger
2022-06-22 21:44:040c7317d50d330217fbd9c66f8f563120ad3155c3094e1b837dad23cc862c60b5exeRedLineStealer
2022-06-22 21:32:1510aaa49fc2023480ff5a6a25e478df0c62bb3688ab615ca22839bdbf6a6ce745exeRemcosRAT
2022-06-22 21:31:080e5c9966da705047c1eb5108fd658f512adafe31f93e625b0e2c00f13999c6afexeFormbook
2022-06-22 21:31:04f67ab014d17685565e8be3dacad4787c1ef63825b07e0a3072ab178598eb6bbfexeMassLogger
2022-06-22 21:25:0468a4f4003de8fc74e3076786f37523f01c884ad54af8d659a98b87ddcf63f98dexeAgentTesla