URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: webservicesamazin.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-14 16:11:04 UTC
Total malware sites :28
Online malware sites :0 (0%)
Offline Malware sites :28 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-07-07 17:08:50 99.83.154.118a51062ecadbb5a26e.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-07-14 16:11:07 128.199.243.169Not listedAS14061 DIGITALOCEAN-ASN- SGno
2021-07-14 16:11:07 163.172.213.69163-172-213-69.rev.poneytelecom.euNot listedAS12876 AS12876- NLno
2021-07-14 16:11:07 208.83.69.35ignignokt.mudkips.netNot listedAS22438 CLEAR-RATE-COMMUNICATIONS- USno
2021-07-14 16:11:07 185.21.216.153thisis.feralhosting.comNot listedAS200052 FERAL- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-15 10:44:05http://webservicesamazin.com:8088/styles/file11...Offline32 Dridex ext exe zbetcheckin
2021-07-15 08:58:06http://webservicesamazin.com:8088/js/Invoice%20...OfflineCobaltStrike ext Dridex ext excel zbetcheckin
2021-07-15 02:22:06http://webservicesamazin.com:8088/tpls/file5.binOffline32 Dridex ext exe zbetcheckin
2021-07-15 02:22:04http://webservicesamazin.com:8088/bundle/file11...Offline32 Dridex ext exe zbetcheckin
2021-07-15 02:16:03http://webservicesamazin.com:8088/bundle/Invoic...OfflineDridex ext excel zbetcheckin
2021-07-14 21:02:22http://webservicesamazin.com:8088/templates/fil...Offline32 Dridex ext exe zbetcheckin
2021-07-14 20:59:17http://webservicesamazin.com:8088/images/detail...OfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:59:11http://webservicesamazin.com:8088/wp-content/fi...OfflineDridex ext Cryptolaemus1
2021-07-14 20:59:09http://webservicesamazin.com:8088/wp-content/fi...OfflineDridex ext Cryptolaemus1
2021-07-14 20:59:08http://webservicesamazin.com:8088/styles/file13...OfflineDridex ext Cryptolaemus1
2021-07-14 20:58:57http://webservicesamazin.com:8088/js/file1.binOfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:58:51http://webservicesamazin.com:8088/bundle/file4.binOfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:58:44http://webservicesamazin.com:8088/img/file6.binOfflineDridex ext Cryptolaemus1
2021-07-14 20:58:36http://webservicesamazin.com:8088/images/file13...OfflineDridex ext Cryptolaemus1
2021-07-14 20:58:29http://webservicesamazin.com:8088/wp-theme/file...OfflineDridex ext Cryptolaemus1
2021-07-14 20:58:20http://webservicesamazin.com:8088/wp-theme/file...OfflineDridex ext Cryptolaemus1
2021-07-14 20:58:09http://webservicesamazin.com:8088/styles/file1.binOfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:57:56http://webservicesamazin.com:8088/vendors/file1...OfflineDridex ext Cryptolaemus1
2021-07-14 20:57:54http://webservicesamazin.com:8088/bundle/file8.binOfflineDridex ext Cryptolaemus1
2021-07-14 20:57:52http://webservicesamazin.com:8088/css/file4.binOfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:57:11http://webservicesamazin.com:8088/fonts/file1.binOfflineCobaltStrike ext Dridex ext Cryptolaemus1
2021-07-14 20:57:09http://webservicesamazin.com:8088/css/file5.binOfflineDridex ext Cryptolaemus1
2021-07-14 20:53:07http://webservicesamazin.com:8088/wp-theme/file...Offline32 CobaltStrike ext Dridex ext exe zbetcheckin
2021-07-14 20:40:50http://webservicesamazin.com:8088/fonts/file10.binOffline32 Dridex ext exe zbetcheckin
2021-07-14 17:54:09http://webservicesamazin.com:8088/themes/Invoic...OfflineDridex ext excel zbetcheckin
2021-07-14 17:54:04http://webservicesamazin.com:8088/img/file2.binOffline32 Dridex ext exe zbetcheckin
2021-07-14 17:38:33http://webservicesamazin.com:8088/css/file7.binOffline32 Dridex ext exe zbetcheckin
2021-07-14 16:11:07http://webservicesamazin.com:8088/fonts/file3.binOffline32 Dridex ext exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-16 11:37:19036273355f6f950af30cbc0cfdc5523a7ab379e58cb2f66c95623cf1ae2e851aexe Dridex
2021-07-16 10:54:4597ba94455db3e0259e67f4be2f7c0dc16f4a1493e881ff82dc4cd3a3c11134badoc  
2021-07-16 10:42:43791d5245da5b79ab8a0c3af821e1d3e0806728c3b74176613f51ab8219b2d2b1doc  
2021-07-16 09:09:55c9df658451b7a1b6921f458380276bfed20dfb12636220c4f8bbee22bb93f229doc  
2021-07-16 09:09:3928232eda9588a70a540369504c2b275b7c4c412328a32208d9580330af20838edoc  
2021-07-16 08:27:01d737862c68f5ef1ae75c5d713ca26e6a9d313f03c616d6fad369c904851dfe69doc  
2021-07-16 06:31:544a016f238e376fc448ac2a78b97ab96b71ca44feaf04abcd9e05432f538208e2doc Dridex
2021-07-16 05:45:2801ef4276955f26ed480073749d44ef5402b5771478af68674d519b808ce803d3doc  
2021-07-16 05:38:42c4f1bc3b201eea1e8226d2c8701d2f7c3641282b9e21ab0f8f72df45a1bb4f2fexe Dridex
2021-07-16 05:37:47b6587631ba47dcd1790e7dd379f73852cee70185a8502f898bfd93e9580d5c34doc CobaltStrike
2021-07-16 05:31:26e0dd0f0cb5617424dc0675c0f8459cc26693cdf3b688fb7d33673f899fdc1a8aexe Dridex
2021-07-16 04:21:273accc9673d2374229ffda51598e98611357bd0502f72f29b16d70dc389f47131exe Dridex
2021-07-16 03:14:2917ce3fefe240a4ce6b7af0dec19e00e8ecb8264271d7f0b356d66cffbe0d558ddoc Dridex
2021-07-16 02:39:48ecaaa3a14f4e90d31391180b0b045fb4368b7a9cf6ccaf0451723ed5fb42a492doc Dridex
2021-07-16 02:32:24bff8bde10296c5f7d8440926fde2024c10f2693ca441a73d8b169094e8a19603doc Dridex
2021-07-16 02:30:12d5cbd2a7676668d473599aa8b457c437a6b655cde407d83865b05a39239427a5doc Dridex
2021-07-16 01:49:0136063ca68cf6aff2388c22f8c1a53db75f292f3fe9446f8355fb74d3390cd3ffdoc  
2021-07-16 00:54:40908967fb8a14010c68e6f136974b47ae1ebdec6b2c71d71f5c0502ad8c5d0a85doc Dridex
2021-07-16 00:29:11fa8142ac6a9744a1a1606dfb7090b8e77491861bb642f265c90491ca2bc4f07fexe Dridex
2021-07-16 00:29:095a3b76b3085ba1efee7031f040554636670ee61031768c1002e563f26d48d50adoc Dridex
2021-07-16 00:00:48a5ae07473849ade19d43dc4e192a54dc6865e92ec3b9df2fec6b90014e13275eexe Dridex
2021-07-15 23:56:283f73a13bbe94d9044bf76f6b66afdb90af8e6c150d2ceda8bc51faf152fd6d2fexe Dridex
2021-07-15 23:52:17e2513cdde6122ff672fd083f66437c6677fa473d161cb81cafa0dd0d79d6e977doc Dridex
2021-07-15 23:49:56d2a9b22d3174934695941d76e7ccb6f1179996d746042fab2b498a3e80961a58exe Dridex
2021-07-15 23:49:343f73a13bbe94d9044bf76f6b66afdb90af8e6c150d2ceda8bc51faf152fd6d2fexe Dridex
2021-07-15 23:49:00fb9bdd0b2ef96444ca944c79f91e648b4935f75395d8cc265c3caab7ed38e256exe Dridex
2021-07-15 23:46:13f1beb410134eddabdc61daad7dbf0272e22a3559a35d81f5f831c41f19f40129doc  
2021-07-15 23:10:23ee9729e8f3fbb953938edb3537e4d53a483e5ac45bdcb1bda80bdb1d36602d79doc CobaltStrike
2021-07-15 10:44:05f00e60f5f094abfe9448d10cb84194e73c0e0f2cb52f00d474d6420cb001c579exeDridex
2021-07-15 08:58:060780d67931c09ff7844aac62d057c059ff029b93c35c436038afa65420f83a9axlsCobaltStrike
2021-07-15 02:22:06f1da83287dc71efd8d39d03f2c349830826b9c8698b0a7bb6cc6e7eb959428daexeDridex
2021-07-15 02:22:03f00e60f5f094abfe9448d10cb84194e73c0e0f2cb52f00d474d6420cb001c579exeDridex
2021-07-15 02:16:032cc14e8b36412790f8ba35b56ca5aa42e3308d4e3bb13a068890a6b2edaab5aaxlsDridex
2021-07-14 21:11:451e7cff422cd9fda456283527e027500af16f9ceceeb23467d55839286b14a8eaexeDridex
2021-07-14 21:11:424600e7951a48232623a4c9eaae2209d2a56e6d174d9a5da837fcc4be143f67faexeDridex
2021-07-14 21:02:197bc8e2b75d876bfbd12297c6eb01d2a09f0694242ad22559e1be6736dc237a37exeDridex
2021-07-14 20:59:179af4b3b8c67d21fef69dee132cb686d1cb9e34e2d5e807b05c2a92e48f08dd39exeCobaltStrike
2021-07-14 20:59:111e7cff422cd9fda456283527e027500af16f9ceceeb23467d55839286b14a8eaexeDridex
2021-07-14 20:59:098e2d3f6bc5f7b639638d2f5ec751bc2985f1636005131623c5d2c448885c5d89exeDridex
2021-07-14 20:59:08672ace07423b11c65be0e0cfcdea8e8a17517b033324b418a1b92d6139daa18dexeDridex
2021-07-14 20:58:57956e66f820c127b655c4e59af455c4cc827d43b111f4cf260b6da1d30ac443b2exeCobaltStrike
2021-07-14 20:58:517c4ec96ba82e79cb37c6829a595dc09b76568a5dadd82c743c3f9a69c985ad83exeCobaltStrike
2021-07-14 20:58:448e2d3f6bc5f7b639638d2f5ec751bc2985f1636005131623c5d2c448885c5d89exeDridex
2021-07-14 20:58:36672ace07423b11c65be0e0cfcdea8e8a17517b033324b418a1b92d6139daa18dexeDridex
2021-07-14 20:58:09956e66f820c127b655c4e59af455c4cc827d43b111f4cf260b6da1d30ac443b2exeCobaltStrike
2021-07-14 20:57:564600e7951a48232623a4c9eaae2209d2a56e6d174d9a5da837fcc4be143f67faexeDridex
2021-07-14 20:57:54277089cb78a9c493cecd8f5fbe70df0577d4f9557fb8b55ff5f7c2505308ca3aexeDridex
2021-07-14 20:57:527c4ec96ba82e79cb37c6829a595dc09b76568a5dadd82c743c3f9a69c985ad83exeCobaltStrike
2021-07-14 20:57:11956e66f820c127b655c4e59af455c4cc827d43b111f4cf260b6da1d30ac443b2exeCobaltStrike
2021-07-14 20:57:09f1da83287dc71efd8d39d03f2c349830826b9c8698b0a7bb6cc6e7eb959428daexeDridex
2021-07-14 20:56:421e7cff422cd9fda456283527e027500af16f9ceceeb23467d55839286b14a8eaexeDridex
2021-07-14 20:53:07923de5fc24a860522375e93ea09e4298e5a1dfaa6a17c61754162aa3d4339bceexeCobaltStrike
2021-07-14 17:55:42d93210076662115315a8713a18a86f22051c45ab7216129daa9b5638a76dac43exeDridex
2021-07-14 17:54:086f8f1b26324ea0f3f566fbdcb4a61eb92d054ccf0300c52b3549c774056b8f02xlsDridex
2021-07-14 17:54:047bc8e2b75d876bfbd12297c6eb01d2a09f0694242ad22559e1be6736dc237a37exeDridex
2021-07-14 16:11:079ffe349bfcaac3ceffbbb5accf85814b0e08d204a02b63a9df9681235a464eccexeDridex