URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: updatessoftware.b-cdn.net
Domain registrar:Name.com -
Domain registration date:2016-04-25 23:34:57 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-08-12 06:35:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :26

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-17 19:14:32 185.111.111.160185-111-111-160.bunnyinfra.netNot listedAS212238 CDNEXT- DEyes
2025-11-27 19:58:33 169.150.247.37169-150-247-37.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-08-13 00:45:01 169.150.247.34unn-169-150-247-34.datapacket.comNot listedAS60068 CDN77- DEno
2025-08-19 19:40:59 169.150.247.33unn-169-150-247-33.datapacket.comNot listedAS60068 CDN77- DEno
2025-08-12 12:39:08 138.199.36.11138-199-36-11.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-08-12 11:31:14 138.199.37.227138-199-37-227.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-08-16 21:33:23 79.127.216.11179-127-216-111.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-08-14 16:56:41 185.111.111.159185-111-111-159.bunnyinfra.netNot listedAS212238 CDNEXT- DEno
2025-08-14 01:18:22 138.199.36.9138-199-36-9.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-11-20 18:30:59 169.150.247.39169-150-247-39.bunnyinfra.netNot listedAS60068 CDN77- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-12 06:35:15https://updatessoftware.b-cdn.net/lev/shadow/rm...OfflineRemoteManipulator ext JAMESWT_WT
2025-08-12 06:35:14https://updatessoftware.b-cdn.net/john/pr/04.08...OfflineHijackLoader JAMESWT_WT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-12 06:35:15969d33185b13535bcf1d50d26186fdf19b5cc6a8f3071bf73180294234ae52d7msiRemoteManipulator
2025-08-12 06:35:14caf3877f85e14b20b648485b77ae01af8db4ac302a4afc55b3f751e78e2c9925msiHijackLoader