URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: wp.ameyiando.com
Domain registrar:Namecheap -
Domain registration date:2025-09-15 08:57:06 UTC
Spamhaus DBL :Botnet C&C domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-08-05 12:38:20 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-08-14 13:59:15 195.177.94.9292.94.177.195.in-addr.arpaSBL694582AS214961 STELLARGROUPSAS- FRno
2026-08-14 07:48:28 94.154.32.220SBL686491AS214961 STELLARGROUPSAS- FRno
2026-08-13 14:25:01 195.177.94.2828.94.177.195.in-addr.arpaSBL694582AS214961 STELLARGROUPSAS- FRno
2026-08-12 02:14:52 94.154.32.103SBL686491AS214961 STELLARGROUPSAS- FRno
2026-08-07 07:09:38 94.154.32.59SBL686491AS214961 STELLARGROUPSAS- FRno
2026-08-06 02:25:48 94.154.32.52SBL686491AS214961 STELLARGROUPSAS- FRno
2026-08-05 12:38:35 195.177.94.210210.94.177.195.in-addr.arpaSBL694582AS214961 STELLARGROUPSAS- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-08-11 09:04:21http://wp.ameyiando.com:8888/web/office365com.datOfflineAgentTesla ext abuse_ch
2026-08-05 12:38:36http://wp.ameyiando.com:8888/web/updated-phanto...OfflinePhantomStealer abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-11 09:04:204180269c675c26e85d20a22f06587a5a45e6f4af5ee4a60fb73dc51317ce50e7exeAgentTesla
2026-08-06 02:25:458f6f78a3e78c282fa75cc96b5ad6b2c5083ca05bdde8ebe8b4f32bce6f64adf4exePhantomStealer