URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: stepco.ro
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-21 12:11:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-01 04:59:07 85.9.47.161cw85-i-dg161.romania-webhosting.comNot listedAS5606 GTS-BACKBONE- ROyes
2021-01-16 19:34:28 85.9.47.16cw85-i-dg16.romania-webhosting.comNot listedAS5606 GTS-BACKBONE- ROno
2025-04-27 23:40:22 89.42.218.218server-0317.whmpanels.comNot listedAS205275 ROMARG- ROno
2020-09-21 12:11:05 5.154.179.176Not listedAS201748 INFOTELECOM- ESno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-21 12:11:05https://stepco.ro/wij87mvg.txtOfflineDLL. Dridex ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-22 20:24:2717d920e9b84db3662346ab38770dd8d37ada30a508f0315ffbcec163e71b7a7fdll  
2020-09-21 17:07:39da98b833c6024d29d64368012fce422ce1396fc057c0c51990e6d29ef5cdea66dll  
2020-09-21 15:38:0831d883327033b6efb446e9416952c638152072095e6fbfab537b74bee477b6cadll Dridex
2020-09-21 12:11:055d2e121c650aea3012ab7891236953dd3b09672788a7be2e4a74716c59e94d98dllDridex