URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | upload-wefiles.com |
|---|---|
| Domain registrar: | Namecheap ![]() |
| Domain registration date: | 2022-08-31 04:44:49 UTC |
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Not blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2023-04-21 06:07:03 UTC |
| Total malware sites : | 3 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 3 (100%) |
| A record(s) observed : | 10 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2023-08-17 18:35:19 | 192.64.119.70 | Not listed | AS22612 NAMECHEAP-NET | US | no | |
| 2023-08-17 09:58:45 | 45.15.158.247 | scared-pie.aeza.network | SBL655671 | AS60042 OnTelecom-AS | RU | no |
| 2023-08-15 14:01:01 | 188.114.96.3 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-08-15 14:01:01 | 188.114.97.3 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-07-13 13:24:04 | 38.242.138.203 | fergo-node2.fearvm.com | Not listed | AS51167 CONTABO | FR | no |
| 2023-06-03 14:21:52 | 194.110.247.127 | verificatienu.com | Not listed | AS200019 AlexHost | MD | no |
| 2023-05-09 21:34:43 | 77.72.7.188 | storm-competitions-frontend-4.cloud.hiltonhosting.com | Not listed | AS12488 KRYSTAL | GB | no |
| 2023-04-21 06:07:05 | 104.21.29.216 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-04-21 06:07:05 | 172.67.171.222 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2023-05-03 23:01:48 | 185.252.179.21 | Not listed | AS214238 iwihost | AE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-04-22 01:53:05 | https://upload-wefiles.com/svchost.exe | Offline | 32 exe RedLineStealer | |
| 2023-04-22 01:22:10 | https://upload-wefiles.com/download/slip.exe | Offline | 32 exe | |
| 2023-04-21 06:07:05 | https://upload-wefiles.com/download/toba22bbc.exe | Offline | AgentTesla |
The table below shows recent payloads delivery by this host.

RU
FR
MD
GB
AE