URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 핵샵.com
Domain registrar:Namecheap -
Domain registration date:2024-01-02 03:43:07 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-12-06 09:21:05 UTC
Total malware sites :2
Online malware sites :2 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2024-12-06 09:22:22 UTC
Oldest active malware site :2024-12-06 09:22:11 UTC (Age: 1 year, 5 month, 28 days, 6 hours, 5 minutes)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-06 09:22:11 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ayes
2024-12-06 09:22:11 188.114.97.3SBL691350AS13335 CLOUDFLARENETn/ayes
2025-11-05 04:54:55 188.114.96.12SBL687667AS13335 CLOUDFLARENETn/ano
2025-11-05 04:54:55 188.114.97.12Not listedAS13335 CLOUDFLARENETn/ano
2025-03-25 00:43:32 104.21.89.169Not listedAS13335 CLOUDFLARENETn/ano
2025-03-25 00:43:30 172.67.162.56Not listedAS13335 CLOUDFLARENETn/ano
2024-12-06 19:05:36 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2024-12-06 19:05:35 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-06 09:22:22https://xn--yh4bx88a.com/storage/files/9/%E2%98...Onlineulise abus3reports
2024-12-06 09:22:11https://xn--yh4bx88a.com/storage/files/9/%E2%AB...Onlineulise abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-08 09:03:41d4751f5dfbbce20bf079914f4418af5bde574ac6469b8e1efc343b60a181f6a6zip  
2025-06-08 08:55:192066863d9134626416c7238902a18852dd1cd23b0abea0e3e1c27f7bbfde5fc4zip  
2025-01-28 23:22:03c665b610032f46ec14b0c37e788363c73e789d87cad1818bbc5726ff732c9341zip  
2024-12-21 07:33:462e6d849bc5e5a901c83a593179d627c5c0a70fe3bca468171e1fb83b9da0e303zip  
2024-12-21 04:34:505c2def5fc89f17438361a7339716efa75fac0921fa449f0679a85e5a723df9ddzip  
2024-12-06 09:22:13e66db2e13fac1a696c7309680fd693ba57244d8455400dc00f5bfff0acfcd25azip  
2024-12-06 09:22:1128ec5f07e0b457624ad1820888159050383fe0aa87ece11ac25302e06dc538b9zip