URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.blackhattoolz.com
Domain registrar:Namecheap -
Domain registration date:2009-04-10 21:38:35 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-03-18 04:50:07 UTC
Total malware sites :4
Online malware sites :3 (75%)
Offline Malware sites :1 (25%)
Newest active malware site :2025-04-20 11:13:09 UTC
Oldest active malware site :2024-03-18 04:55:09 UTC (Age: 2 years, 2 months, 20 days, 10 hours, 12 minutes)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-03-18 04:51:05 104.26.0.13Not listedAS13335 CLOUDFLARENETn/ayes
2024-03-18 04:51:05 104.26.1.13Not listedAS13335 CLOUDFLARENETn/ayes
2024-03-18 04:51:05 172.67.72.30Not listedAS13335 CLOUDFLARENETn/ayes
2025-11-22 01:05:26 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2025-11-22 01:05:26 188.114.97.3SBL691350AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-20 11:13:09https://www.blackhattoolz.com/licensing/updates...Online10pluspositivesinVT abus3reports
2024-03-18 05:41:22https://www.blackhattoolz.com/licensing/deploym...Online32 exe zbetcheckin
2024-03-18 04:55:09https://www.blackhattoolz.com/licensing/updates...Online32 exe zbetcheckin
2024-03-18 04:51:05https://www.blackhattoolz.com/licensing/updates...Offline32 exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-20 11:13:07245ca8606dfe5a135397e8ca2879d5b864b645b476a23eabff08588796b55c77exe  
2025-01-22 15:02:3184db57ee6a5e16b875e27f18cd2faeabb5c6f7e16dfa48a24868e8f3c30fab94exe  
2024-12-04 18:39:08c1ca8dbd7052700872c7224f90f003c022473c737d0f38e430bce8cab947a850exe  
2024-10-30 17:59:45e8de69b5c71b0e976f4755bba3be551e326d9c0430395310291fb59688e0a1c3exe  
2024-10-11 17:43:02b159a66cb1f76e190589d6510f91e943ba0785dd1ad29736dd15f979cf2bbe9cexe  
2024-09-23 18:23:50b76a5d0589fdbb0189a00c68dc23236f7818cc76ed00dabc848592ad20afbdb9exe  
2024-09-05 16:43:5441853d91b1ea1a9fbc492589d25aa6f515ca0ad241ce844af76c55a795873ed9exe  
2024-08-22 19:37:5469b3ef30789333914bf841ba431190799f643b9b80573378ddd020795cad7db1exe  
2024-08-21 15:04:02209800aca2ca48387ed5dbdd844d24b6dd5c58a8dc07842fbf7fc1a96020732cexe  
2024-08-08 23:09:46516a63807d850854ac64c4cee0f01eb2666ab1b51abcdc34f5dcc143f1c00228exe  
2024-08-08 19:08:07852974384ac4e2982afc787972b490b869ab1fe8fda2df4495f8df66e4e9d0b9exe  
2024-07-23 15:31:36df43a61fd20ee2672c7230c0cfec9425041b68c536f76532b318fb7841c99bddexe  
2024-07-16 15:01:547113c05a36f37f46144c04b6f38ff49cf13b2923f8ec9eb53a31484a7cd731e7exe  
2024-06-26 15:09:145e406500a8856df0e02162f1a4f41aa3c14ee7f8c743a5fcea206a882996ec0eexe  
2024-06-22 18:19:251aa1306fa14b0f60e848c4397a1763624aa674791779795bea38465b857427d2exe  
2024-06-10 11:08:007eb64da2492a826c4f462c4f89bea2d1c42db510d02fa66b06cc715b920b79e4exe  
2024-05-30 18:18:49b72a0b66b6a1bfb43527711cf8f70bcfd0502d02b29d70c4b8a097c96aa07bc7exe 
2024-04-25 19:17:2375ee72660f6028570af19336c52fa3dd5bff290d104dd9d1f6291ac9d30ecfa5exe  
2024-04-17 18:33:31e9ac29ed821b200695fd4d4f66959fddfac5474dd6f2380b051dd0ad2e114173exe  
2024-04-02 19:19:24346eae7ef7ffed41c2f3f18beafe2bb6692a94323700f0cade748ba83e55eb34exe  
2024-03-25 15:08:460e99fabaa30e3ab72b09397bc9922dc8d29ae37bf702301c4a593a693437620fexe  
2024-03-18 06:11:3152d5d347126a7a686f2da37c2e8868f4bcec2e5affabd850ad45f2b81b21b664exe 
2024-03-18 04:55:09b5c182f64cd01e09b9806c1ce4763e384defcad28972d7f66d895eca54b0d8daexe 
2024-03-18 04:51:05a4071bcbccf061ccae8b89c4e87353fd3a2db2bc2e3ea97e7b83fc9391b271ccexe