URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host 6.u0141023.z8.ru.

Database Entry

Spamhaus DBL:Not listed
SURBL:Not listed
Firstseen:2018-12-04 04:30:02 UTC

IP addresses

The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-12-04 04:30:03195.208.1.105std-carp5-http.nic.ruNot listedAS25535 ASN-RUCENTER-HOSTING- RUyes

Malware URLs

The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2018-12-07 13:10:25http://6.u0141023.z8.ru/yfXx0LnOfflineemotet epoch2 exe heodo Clean@Cryptolaemus1
2018-12-07 00:50:04http://6.u0141023.z8.ru/Bc2ndsb1aVB9C0X2/SWIFT/Firmenkunden/Offlinedoc emotet epoch2 heodo Clean@Cryptolaemus1
2018-12-05 12:12:39http://6.u0141023.z8.ru/Bc2ndsb1aVB9C0X2/SWIFT/FirmenkundenOfflineemotet epoch2 heodo Clean@Cryptolaemus1
2018-12-04 11:49:06http://6.u0141023.z8.ru/scan/US/Paid-InvoicesOfflinedoc heodo Clean@zbetcheckin
2018-12-04 07:37:03http://6.u0141023.z8.ru/default/gescanntes-Dokument/Zahlu...Offlinedoc emotet epoch2 heodo Clean@Cryptolaemus1
2018-12-04 04:30:03http://6.u0141023.z8.ru/default/gescanntes-Dokument/Zahlu...Offlinedoc heodo Clean@zbetcheckin