URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: temp.sh
Domain registrar:Porkbun -
Domain registration date:2018-12-19 18:28:50 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-04-10 03:26:09 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-01-01 01:35:11 51.91.79.17vps-6853bc8f.vps.ovh.netNot listedAS16276 OVH- FRyes
2023-10-03 21:54:07 213.186.33.5redirect.ovh.netNot listedAS16276 OVH- FRno
2022-10-20 16:24:19 47.87.229.39Not listedAS45102 ALIBABA-CN-NET- USno
2022-10-05 21:17:56 47.87.227.167Not listedAS45102 ALIBABA-CN-NET- KRno
2022-08-25 02:09:08 149.57.163.132Not listedAS64286 LOGICWEB- USno
2022-07-08 21:30:07 149.57.165.247Not listedAS64286 LOGICWEB- USno
2022-04-10 03:26:10 172.245.52.149172-245-52-149-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- IEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-29 09:32:15https://temp.sh/QpheY/zzerr.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2025-08-01 15:03:08https://temp.sh/PXIKt/Test.exeOfflinec2-monitor-auto dropped-by-amadey c2hunter
2025-05-07 10:59:04https://temp.sh/utDKu/138d2a62b73e89fc4d09416bc...Offlineexe abuse_ch
2025-04-24 11:22:10https://temp.sh/uCQTT/main.vbsOffline iLikeMalware
2025-04-24 11:21:02https://temp.sh/GjHAk/s.exeOffline iLikeMalware
2025-04-24 11:21:02https://temp.sh/WTbbk/a.exeOffline iLikeMalware
2023-09-08 04:33:05https://temp.sh/MjhuE/Publish-234dkdad.exeOfflinedropped-by-SmokeLoader Casperinous
2023-08-07 15:13:02https://temp.sh/tyujS/test.021.003.exeOfflinedropped-by-SmokeLoader Casperinous
2022-04-10 03:26:10https://temp.sh/LKpNo/SERVER-SMTP.exeOfflineexe AndreGironda

The table below shows recent payloads delivery by this host.