URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: synth-node.dialectraforge.in.net
Domain registrar:Public Domain Registry -
Domain registration date:1994-10-26 04:00:00 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-04-09 03:42:10 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-09 03:42:13 104.21.52.99Not listedAS13335 CLOUDFLARENETn/ano
2026-04-09 03:42:13 172.67.198.15Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-09 03:42:13https://synth-node.dialectraforge.in.net/05fe31...OfflineACRStealer ClearFake NetSupport ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-09 22:00:2568f85c1850d344a75592c49b29cb04672068ce3fa5c66c8e1afab4301cd6c8d5dll  
2026-04-09 16:55:32320e57b0129c5a28f923e01c7c45139142f28703c4387fa7b3774398cd5e92c1dll ACRStealer
2026-04-09 10:33:51c131d9943741563152262d0ce82d6ef411431c6f4f28ca168d08eafea73f2a1cdllNetSupport
2026-04-09 03:42:13328e097831c74290f102dcf11c41bc4b7b82a37681d8df3690783ea8a9e3bebcdllNetSupport