URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host www.nexxtech.fr.

Database Entry

Spamhaus DBL:Not listed
SURBL:Not listed
Firstseen:2019-02-10 00:27:16 UTC

IP addresses

The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-05-30 04:53:3191.207.18.100host100.100pour100net.comNot listedAS8218 NEO-ASN legacy Neotelecoms- FRyes
2019-04-12 07:40:38151.80.147.126126.ip-151-80-147.euNot listedAS16276 OVH- FRno
2019-02-10 00:27:27163.172.104.96sd.equipocash.comNot listedAS12876 AS12876- FRno

Malware URLs

The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2019-02-16 04:53:33http://www.nexxtech.fr/clients/eof/cascades/messg.jpgOfflineexe payload Ransomware stage2 Troldesh Clean@shotgunner101
2019-02-10 03:55:02http://www.nexxtech.fr/css/fonts/font-awesome/css/ashan.r...Offlinecompressed javascript Loader Ransomware stage1 Troldesh zip Clean@shotgunner101
2019-02-10 01:39:04http://www.nexxtech.fr/interactifs-aceto/messg.jpgOfflineexe Troldesh Clean@zbetcheckin
2019-02-10 01:36:02http://www.nexxtech.fr/css/fonts/font-awesome/css/messg.jpgOfflineexe Troldesh Clean@zbetcheckin
2019-02-10 00:27:27http://www.nexxtech.fr/js/views/messg.jpgOfflinecompressed exe javascript Loader payload Ransomware stage1 stage2 Troldesh zip Clean@shotgunner101