URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5star.rent
Domain registrar:REG.RU -
Domain registration date:2021-03-22 09:11:59 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 19:45:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-23 19:41:30 194.67.71.155Not listedAS197695 AS-REGRU- RUno
2022-01-11 19:45:05 87.236.19.174m2.halflife3.beget.comNot listedAS198610 BEGET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 19:45:05http://5star.rent/wp-content/W4lIwiQ0aL/Offlineemotet ext epoch4 redir-doc xls waga_tw
2022-01-11 19:45:05http://5star.rent/wp-content/W4lIwiQ0aL/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 01:22:17926c822e2c4d78b252f788d3fa75a77bfed1380ad50cdacf21f3efddf15b0b26xlsSilentBuilder
2022-01-12 01:04:559d277bf6e9b937c6b9d79db16b78f65ef5346b79c5c68fd3fda71a4e18171fe7xls SilentBuilder
2022-01-12 00:33:15f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feeaxls SilentBuilder
2022-01-12 00:08:26f710943ccdadad818f80e208b3ea05bb57523b5ca7ff2e9647abe730a65afe5fxls SilentBuilder
2022-01-11 23:58:281bd3d0d3bef771b182e3de5670d6f9515c73b76cf971203cccba88fb2dd3ddbbxlsSilentBuilder
2022-01-11 23:27:155a9b4efcbf4e2f0517f9d0b39ad038e37ec003dc7c2021213c7db00147268727xlsHeodo
2022-01-11 23:08:325c5fd037c414e33a6538da72a5ea4ae89c8dac15b396b6a10e8504a0b5a7ee75xlsHeodo
2022-01-11 22:43:20e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091xlsHeodo
2022-01-11 22:08:21f062c2a1622bb6bbddf6250cae210e3c341320104c09b649e9748bb7ad87c232xls SilentBuilder
2022-01-11 21:51:13755b4ee15682c5a1e3567c5d710b241e03a8b6ce7080dc3ef0816be9ed6e06f7xlsSilentBuilder
2022-01-11 21:30:399ade9daf48cb63c929cd8e7ec03ac77ed41d362efaa79453d0eda4553747c404xlsSilentBuilder
2022-01-11 21:06:311db259b0063d26f9af684e7246d336250e289514a4e900eab1337ee9981a866bxls Heodo
2022-01-11 20:46:47416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dxlsSilentBuilder
2022-01-11 20:18:39d92b0ebb1f64086c8c4d5b238f3683a3319bcf041cdfc9e6736f742a260a5ce2xlsSilentBuilder
2022-01-11 20:02:011ee39644692931c717336eb3e00db7e82c9a27e987a8931e45d3eca7abd009c1xls Heodo
2022-01-11 19:45:051d96974b58892da12aaa0cb2cbc9dc3987c299c4e6aa20c85fba9b95ed4deb62html  
2022-01-11 19:45:053899ca2b33a93a2fc87600b6a1d7688827c1c0deb9626e60e5691a0fcf47e10fxls SilentBuilder