URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: winderswonders.com
Domain registrar:Namecheap -
Domain registration date:2023-10-29 15:50:37 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-01-11 14:32:04 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-01-11 14:32:06 173.233.84.234webserver97.turnkeywebspace.comNot listedAS40244 TURNKEY-INTERNET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-02-10 11:34:14https://winderswonders.com/JK/mn.txtOfflineascii AsyncRAT ext Encoded xworm abuse_ch
2024-02-10 11:34:09https://winderswonders.com/JK/nm.txtOfflineascii AsyncRAT ext Encoded xworm abuse_ch
2024-01-17 07:29:05https://winderswonders.com/JK/cBCyCJ71.binOfflineCloudEye encrypted xworm e24111111111111
2024-01-16 20:41:06https://winderswonders.com/JK/Domstole.pfbOfflineAnonymous
2024-01-16 20:40:08https://winderswonders.com/JK/YZMdDhRxNMLXTJ188...OfflineAnonymous
2024-01-11 14:32:06https://winderswonders.com/JK/Sargassotang.snpOfflineGuLoader ext SVG Anonymous
2024-01-11 14:32:06https://winderswonders.com/JK/Benzoquinone.acaOfflineGuLoader ext SVG Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-02-10 11:59:320da7d1cb764403706d1b6db66ff1ae09ae75c641c1ab4f73065cd24a870275b7txt AsyncRAT
2024-02-10 11:34:140da7d1cb764403706d1b6db66ff1ae09ae75c641c1ab4f73065cd24a870275b7txt AsyncRAT
2024-01-17 07:29:05ef2f3f65d1e8cf1e3dff1a8b627ccd71f985a64dc52575d8c7bb4dc8df624a5funknown  
2024-01-16 20:40:084fbc5561c85057d529e1d2b4fa69bade52247f73d123cf07bdaeff15860f8714unknown