URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 51zqwp.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-14 11:04:11 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-14 11:04:15 152.136.226.250Not listedAS45090 TENCENT-NET-AP- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-14 11:04:15http://51zqwp.com/ozbun/DOC/yebg2g48/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-15 10:28:4255f8854dbcaa2832aa10f768c129ab27544b5b153c7e4ea008f7ae9444681eecdocHeodo
2020-08-15 09:59:58e3dc10847c610fb756b701eb6c9eff581d98adda60bbd1df9ca1c41f43e6710fdocHeodo
2020-08-15 09:30:33a570a76cfdaf487a4b7306a5c2212e3f7ea7f2ef673e1f9819090cf6e84abe5bdocHeodo
2020-08-15 09:13:4972af635d51194d2ab428924c2c7f51aa4a9d040e93566ed7302ed43f5fa16eeddocHeodo
2020-08-15 08:53:1159931fc10797afb244cd5fad842662e6195c228946e63c010c8d619147c57a21docHeodo
2020-08-15 08:31:26e4755fb87595acbe2efa782aba44cec85fc8e2fc968d3e54d60b9459ed8b4c9cdocHeodo
2020-08-15 07:44:07ee97f9a6d45b17138a70dd059c12b950dc5cfd7ea2ea195a0174e656506608c9docHeodo
2020-08-15 06:51:31efaf2ad634e680575e71775d7e7081272a70e9d96a70a2da8691a0e4e95f21aedocHeodo
2020-08-15 05:55:3242cd0e6beccc89544b7f23aad7d7c476b8751a76a55e1c0e054c9609e1f41283docHeodo
2020-08-15 05:37:4339305c6dbc4d4612cfc18efe4df05ca5898cd752b92635429f393159a7734448docHeodo
2020-08-15 05:03:54df46f526192787058b497745baa89076f7a146abf7904a166ff3c88913d6fe8ddocHeodo
2020-08-15 04:47:268bcdcd0930116eda30e116f00f3d77e1d072a59c4aaa832e7c4b4c202b9ad77ddocHeodo
2020-08-15 04:37:520d12b5e9f5f5999ef15565f91ef3a2e631ca0a35c8747a808a542b2a8d8100b2docHeodo
2020-08-15 04:06:075cf289830a79e1608f952fbb47868d1791f30a61fca435f7f76c5bd33b623451docHeodo
2020-08-15 03:35:100a9e7d8e4b00631d24afb44e7e5f6ad531d8024410570195352e9b4666d7141ddocHeodo
2020-08-15 03:02:262fabcc2eb662a103f6fb0067a2d8f0b522149acda448296223c7fe79bdc2e2eadocHeodo
2020-08-15 02:35:062052c0368adb81017535da7aa5dae9846fb5cdd1ad7b3dc089d9c2b7152608bbdocHeodo
2020-08-15 01:03:3302e13d73ecd528b2cf8e528ad97ffd6dae1b2e3e6e443fe37a6877919d9de1c1docHeodo
2020-08-15 00:43:03c1f1f9b4ea3631f3eaf9afa4e8f27d8dcfbcbce4c65a47b6ca4778a833104ec1docHeodo
2020-08-15 00:03:152282676dff6e201e68e1817f507dbb2f5ecbeb498367e7aada3916d32e89511ddocHeodo
2020-08-14 22:31:1075a72a41ab01b2732ce7d72f8099772cfa9eeffd6de415ac468e8f979c38d466docHeodo
2020-08-14 22:13:30c837fd8744bd36a0ac0a3a3f11e102063d60651777ee888c2f3f8e83c54a6483docHeodo
2020-08-14 21:46:38f868e00a4f8d182360784894248a210bb56e707c5a830c89485b157ff1a72402docHeodo
2020-08-14 21:37:015936c071471d7130c47558241c18b4dcac2be07eb3aba3327d251590f952c2aadocHeodo
2020-08-14 21:22:316c2eba2dcea75385e146eb28ffde0be82b8b78f4d943bda7462eebfb283e6c34docHeodo
2020-08-14 20:57:38739eab0c4f294e4ba8fff9f685d6ab8303b5e4ab1caf9482d846afec5aeab316docHeodo
2020-08-14 20:30:2618eac692518c945b0bd23be239abac9df98f3e77f39773df35ac22233f25749cdocHeodo
2020-08-14 19:59:0196b6cab1427a652a35407967a7c4f7e6bb2bd63159d8e2510793ea9b9e76093bdocHeodo
2020-08-14 19:29:22b118fd8dcf97cf570ff2c1e3640e17e7fe7bd4f73b7ec79f4aac13d6b1fcca19docHeodo
2020-08-14 19:03:38508a3ceae3f786124dba30150aba4fce295d13eb1a60afacd789b4f37c2df5c0docHeodo
2020-08-14 18:30:190800f5f92096b10eaffebb3ca43a7a5006b931823de9002d8c9004a5a96eaf9fdocHeodo
2020-08-14 17:01:1092ffc87ebde551d6dec0d9a939474f99575856d4aa63e78b2db40680f2da2188docHeodo
2020-08-14 16:39:480a55fe7bd5ed193a8326b31f8065bd2c338661bdfdd0edd35ade2f95e156a2e2docHeodo
2020-08-14 15:08:35c03a86eed2e8494c8a4b30633903d038ec9ce25e385572cde2045af0127b29a1docHeodo
2020-08-14 14:44:08195495f81ec757b286d74776c59ace3b717a02c3f357abc851fe9702008f66f7docHeodo
2020-08-14 14:20:4664ba6f5e621c011742a0ca7ba63a9416866e59ac3eb1aabaa6b355e2be4d11ffdocHeodo
2020-08-14 12:47:022958931d81ad10eb95bb3fca9457a800e9b4a9459d2727f30cb5d49d7bed0527docHeodo
2020-08-14 12:30:5073cad6ba26fb0aa184d10e24cfdbed4498c47ef40ef010ed07ae719fc7b6b2d4docHeodo
2020-08-14 12:07:5403b564a9e15d001e6a2c08962ee25d99e595b4aee559c6ea7a7dc99b96cec92ddocHeodo
2020-08-14 11:46:5460c6203d9b7a2178fb3f76f12d896c8191aaef13c55973e5a177df215181683ddocHeodo
2020-08-14 11:30:4424798df3b8b05d774f455725548251d62206a0f8498f29914f75dd7086d28389docHeodo
2020-08-14 11:04:152ba31bcf0605c3fb50f7855062c192023371778e906ddbc8f2f9c8812d07a2a0docHeodo