URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: tumanjo.com
Domain registrar:GoDaddy -
Domain registration date:2020-01-13 11:55:59 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-05-24 05:58:03 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-23 18:40:46 174.138.93.182Not listedAS14061 DIGITALOCEAN-ASN- USyes
2025-06-16 08:27:12 192.250.229.176s4143.fra1.stableserver.netNot listedAS209341 WHG-FRA- DEno
2022-10-25 14:06:24 92.204.219.117117.219.204.92.host.secureserver.netNot listedAS21499 GODADDY-SXB- FRno
2023-01-18 18:17:08 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2022-10-03 14:52:31 34.102.136.180180.136.102.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2022-05-24 05:58:04 160.153.133.146146.133.153.160.host.secureserver.netNot listedAS20773 GODADDY- USno
2022-06-04 14:10:46 192.124.249.3cloudproxy10003.sucuri.netNot listedAS30148 SUCURI-SEC- USno

Malware URLs


The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-05-29 16:38:060c722728ca1a996bbb83455332fa27018158cef21ad35dc057191a0353960256exeRecordBreaker
2022-05-29 16:31:300c722728ca1a996bbb83455332fa27018158cef21ad35dc057191a0353960256exeRecordBreaker
2022-05-29 16:29:280c722728ca1a996bbb83455332fa27018158cef21ad35dc057191a0353960256exeRecordBreaker
2022-05-29 16:18:130c722728ca1a996bbb83455332fa27018158cef21ad35dc057191a0353960256exeRecordBreaker
2022-05-26 11:57:079ad06b0e000800a33d381949658dbd0bfd7c7f1025aa5c81621b55f2f69a7a3fexe 
2022-05-25 19:33:049ad06b0e000800a33d381949658dbd0bfd7c7f1025aa5c81621b55f2f69a7a3fexe 
2022-05-25 19:33:04c911528baa904d1f763fbd4f383e44528fbdbb3345403b54c2c92c9ee10294dbexeRedLineStealer
2022-05-25 15:55:04959c0ef7180f57d3159570b691671e9a51833c193d9727d374d7965740fb0b57exeRedLineStealer
2022-05-25 07:39:049ad06b0e000800a33d381949658dbd0bfd7c7f1025aa5c81621b55f2f69a7a3fexe 
2022-05-25 07:38:04959c0ef7180f57d3159570b691671e9a51833c193d9727d374d7965740fb0b57exeRedLineStealer
2022-05-25 07:38:0456ef21b69e3f7eaaae8a29265ab08fdd0f3401c25ed786dc34169bd0594887f1exeRedLineStealer
2022-05-25 06:14:369ad06b0e000800a33d381949658dbd0bfd7c7f1025aa5c81621b55f2f69a7a3fexe 
2022-05-25 00:57:04959c0ef7180f57d3159570b691671e9a51833c193d9727d374d7965740fb0b57exeRedLineStealer
2022-05-25 00:49:0456ef21b69e3f7eaaae8a29265ab08fdd0f3401c25ed786dc34169bd0594887f1exeRedLineStealer
2022-05-24 17:22:0456ef21b69e3f7eaaae8a29265ab08fdd0f3401c25ed786dc34169bd0594887f1exeRedLineStealer
2022-05-24 17:22:04c911528baa904d1f763fbd4f383e44528fbdbb3345403b54c2c92c9ee10294dbexeRedLineStealer
2022-05-24 13:45:2245b74ee8834454e9867c7aaafdb50d861b0f645647fcf12c328c156b415af3d6exe RedLineStealer
2022-05-24 13:40:46f7c781616e39d720a321fe772fd3c5963d9b76f4d77cbb863a447b128bab829eexe RedLineStealer
2022-05-24 13:39:4202e6c166c32137a4a9dd3a23977c8742ab0e3207f8d013c3e630b5d974302379exe 
2022-05-24 12:57:04a0dc657791e6bf1267c8ccb48f337569d9b77f46922c5dd4761010fc7b8f94a6exe 
2022-05-24 05:58:04627898083243468f15943e3752d0ca2c463d2548316d5ca6bca78972c27cd6efexeRedLineStealer
2022-05-24 05:58:046066ada4d9d96be88422f5a2b1fffa410901f9af4308528cbc00145225575e21exeRedLineStealer