URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 1win365.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-17 13:41:08 UTC
Total malware sites :1
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-14 15:52:48 104.21.17.244Not listedAS13335 CLOUDFLARENETn/ayes
2025-11-14 15:52:48 172.67.178.226Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-28 21:42:44 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 21:42:44 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2025-05-25 00:09:08 104.21.82.161Not listedAS13335 CLOUDFLARENETn/ano
2025-05-25 00:09:08 172.67.159.90Not listedAS13335 CLOUDFLARENETn/ano
2020-08-20 12:39:25 154.208.96.19Not listedAS11404 AS-WAVE-1- USno
2020-08-17 13:41:13 23.234.41.152Not listedAS134548 DXTL-HK- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-17 13:41:13http://1win365.com/wp-admin/multifunctional-res...Offlinedoc emotet ext epoch1 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-17 16:59:338a346d540cf74e5dd42aa37659347c7620b972f541ed167bf4ffe7cfcacfe5e5docHeodo
2020-08-17 16:44:25dbecd98d9fd1626b3aa562d063ba66033db39d1b8e846afe8634d738feeda550docHeodo
2020-08-17 15:12:06b8c4ae9395ce9c082cbe508326bbc7a8bc329dd318b3034fde610276c5d2e102docHeodo
2020-08-17 13:41:105488ced86c0349f218ebe8ee794bcca48f54e48b1be0335d03602d5a8b99a90adocHeodo