URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: x-vpn.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-18 17:10:04 UTC
Total malware sites :1
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-24 08:15:49 89.58.51.107107.51.58.89.sinkhole.caad.fkie.fraunhofer.deNot listedAS197540 netcup-AS- DEyes
2025-04-29 00:34:21 188.40.187.155155.187.40.188.sinkhole.caad.fkie.fraunhofer.deNot listedAS24940 HETZNER-AS- DEno
2021-07-25 10:24:26 109.234.32.6363.32.234.109.in-addr.arpaNot listedAS216139 IRONHOST- NLno
2021-07-23 02:14:50 80.85.157.91vtkchel.pserver.ruNot listedAS44493 CHELYABINSK-SIGNAL-AS- RUno
2021-07-20 15:11:36 37.140.192.82server51.hosting.reg.ruNot listedAS197695 AS-REGRU- RUno
2021-07-18 17:10:16 193.164.16.141p.global-it.ruNot listedAS47995 AT-AS- RUno
2021-07-20 23:20:29 104.22.14.57Not listedAS13335 CLOUDFLARENET- USno
2021-07-26 07:29:34 65.21.127.155leela-ip3.handyhost.ruNot listedAS24940 HETZNER-AS- FIno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-18 17:10:16http://x-vpn.ug/afansdo/a.exeOffline32 Amadey exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-07-18 17:10:164194b8d83f6a72469c75a45c7fcfae079989a6883c9dd7dc124d800c57f6fe54exeAmadey