URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: wellcalls.com
Domain registrar:NameSilo -
Domain registration date:2008-10-25 18:46:02 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-23 20:07:03 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-01 21:25:24 44.233.250.75ec2-44-233-250-75.us-west-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2025-11-01 21:25:24 52.38.196.63ec2-52-38-196-63.us-west-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2025-06-09 00:50:40 108.61.73.182108.61.73.182.vultrusercontent.comNot listedAS20473 AS-VULTR- USno
2025-06-09 00:50:40 149.28.227.54149.28.227.54.vultrusercontent.comNot listedAS20473 AS-VULTR- USno
2025-06-06 04:12:59 45.63.4.14545.63.4.145.vultrusercontent.comNot listedAS20473 AS-VULTR- USno
2023-04-25 22:49:07 13.248.169.48a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-04-25 22:49:07 76.223.54.146a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-02-01 06:52:28 13.248.216.40afdda383cf24ec8c3.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-02-01 06:52:28 76.223.65.111afdda383cf24ec8c3.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2022-10-25 10:16:21 72.52.179.174lb01.parklogic.comNot listedAS32244 LIQUIDWEB- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-04-18 15:59:02http://wellcalls.com/TalkMode.exeOfflineexe Formbook ext abuse_ch
2022-04-18 06:24:04http://wellcalls.com/Reelframe.exeOfflineexe Formbook ext abuse_ch
2022-04-18 06:24:04http://wellcalls.com/Sundry.exeOfflineexe Formbook ext abuse_ch
2022-04-11 17:41:04http://wellcalls.com/Unstable.exeOfflineexe Formbook ext abuse_ch
2022-04-11 17:41:04http://wellcalls.com/Railroad.exeOfflineexe Formbook ext abuse_ch
2022-04-09 07:02:06http://wellcalls.com/Rounder.exeOfflineexe Formbook ext abuse_ch
2022-04-08 09:05:05http://wellcalls.com/Shopping.exeOfflineexe Formbook ext abuse_ch
2022-04-08 09:05:05http://wellcalls.com/Imageviewer.exeOfflineexe Formbook ext abuse_ch
2022-04-04 10:30:07http://wellcalls.com/reserve.exeOfflineexe Formbook ext abuse_ch
2022-04-04 10:29:04http://wellcalls.com/AsusFontMode.exeOfflineexe Formbook ext abuse_ch
2022-03-31 15:38:04http://wellcalls.com/random.exeOfflineexe Formbook ext AndreGironda
2022-03-23 20:07:05https://wellcalls.com/RFQ8008.lzhOfflineFormbook ext rar AndreGironda

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-04-18 15:59:0250d25ef6868b83e6b25fdf60d4a2c83824f2278d121babb6a3a548e53bea4ea0exeFormbook
2022-04-18 06:24:04beab53a78651513011c1b0374269a4a282a995650cb9bc7063ae999628e578a2exeFormbook
2022-04-18 06:24:041fba488aa9620978c99b097aa6786588102d91b2b6334b101437dd0377edd216exeFormbook
2022-04-17 07:23:2634f93e7508b3e524b4a13746a05ad33724dbc8c4de2820d0bcea1dd76b59f1ebexe 
2022-04-14 13:07:28b27414851c9c840afb193065ed625799cb7464c6e82a3325a6b68b16affff58fexeFormbook
2022-04-14 08:01:2967435f426cc9f3036d38b4af360f5fc7a4ea547a3e93eccbdf0425718e174dd8exeFormbook
2022-04-14 07:56:466ad94828733d211368d39bc8669735c844df4d7c2265ff4869558c683170e18fexeFormbook
2022-04-11 17:41:04c944efe6f7ebc5786e8db1b3a3b4296daacce868fe45318adf01617050e4ea9eexeFormbook
2022-04-11 17:41:04af3efb1470cc4818ac5cc03b516aa833df1635a311745b78b58406b46886ad04exeFormbook
2022-04-09 07:02:06da3faf405c8673426db7d5e6a59fb74f2cb6e0362b6e280a09024ba97dc98dc7exeFormbook
2022-04-08 09:05:05c0760105fed05b99698c3f1e5bb6ed6e2e9b386315d0e187cd075b8ed5ea7fe5exeFormbook
2022-04-08 09:05:052a48c2b3780f6b0f3fd3f3f05f54066f465870e6f534237a5d283ee079882828exeFormbook
2022-04-08 05:14:17a002227c2d9227812bbfe3c57117f2c5d3bc57b9930158aacdf0da14a2807089exeFormbook
2022-04-07 12:39:52248d88ba77b9221d41aa59d1e05e8aff660a8592b573ddc6d7163cc6cbb59595exeFormbook
2022-04-04 10:30:07cd76d4063992bb159bf31d7cc4ff6dcb4acbbb2c47b5cd6a1de03e5f60bb5c6eexeFormbook
2022-04-04 10:29:045d199f6e3b18707bf891e790552a097e326cb170308a95d4915b1a8e1718a4cfexeFormbook
2022-03-31 15:38:04f140ff41e79cf738d424556d3e3dfa7f7aef0d2d3991faa348d6090cc19f1da4exeFormbook