URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: a-z-riken.co.jp
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 13:49:06 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-05 14:40:36 183.90.245.29sv2028.xserver.jpNot listedAS131965 MAINT-JPNIC- JPno
2022-04-01 08:17:29 163.44.185.163163-44-185-163.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-03-31 22:54:49 163.44.185.180163-44-185-180.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-03-30 22:46:02 118.27.125.192118-27-125-192.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-03-27 10:22:24 163.44.185.189163-44-185-189.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-01-11 13:49:09 157.7.107.61157-7-107-61.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-03-28 08:18:57 118.27.125.191118-27-125-191.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno
2022-03-31 07:06:23 163.44.185.214163-44-185-214.virt.lolipop.jpNot listedAS7506 MAINT-JPNIC- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-19 16:15:06http://a-z-riken.co.jp/wp-includes/hLKlQBzCeTFV...Offlinedoc emotet ext epoch4 SilentBuilder Cryptolaemus1
2022-01-18 06:55:06http://a-z-riken.co.jp/wp-includes/hLKlQBzCeTFV...Offlineemotet ext epoch4 redir-doc xls Cryptolaemus1
2022-01-11 13:49:16http://a-z-riken.co.jp/wp-includes/RMxQYBvM/Offlineemotet ext epoch4 redir-doc Cryptolaemus1
2022-01-11 13:49:09http://a-z-riken.co.jp/wp-includes/RMxQYBvM/?i=1Offlineemotet ext epoch4 heodo ext SilentBuilder xls Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-19 16:15:0595141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294xlsSilentBuilder
2022-01-18 06:55:050d7617f1cf41e01c72e0b21ecc562996bdec69c27b3056db7d3e1958c8213797html  
2022-01-12 02:18:35796cb1dfe07dac51d9dd955ef372b6283adbfc38e34c92ee379fff29c89baccexlsSilentBuilder
2022-01-12 01:55:30d70eea3a457a572c1ee00b87e0c62ad39c9a8307340a7bff3bae0a08ade7c556xlsSilentBuilder
2022-01-12 01:27:21ecaa8fa10f2e5726552f68f4c691133bb782d791b23c96e2c26b5c4838a00e68xlsSilentBuilder
2022-01-12 01:06:04c51d8cb997287ed9a94d3d5dfd322c073e1eeea0634bfe18f7d92a3d7fd85543xls Heodo
2022-01-12 00:34:23a196a7f762ccc713b4c96a96ad4d8d50c3a27964758730b87741f65f609c91abxls SilentBuilder
2022-01-12 00:02:5005dc48ca9e5d5feb04a32c1ef3a8d18453a2a679e7257ce24856895a5dea268bxlsSilentBuilder
2022-01-11 23:46:2366f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6xls SilentBuilder
2022-01-11 23:23:35b5207887a27a42330a6b8e863e0550008a6375de1f4c9c6c0edcc7a9bb6d548fxlsSilentBuilder
2022-01-11 23:04:24d616af039b685a1e393e85dfd6d3558a0a062fc2cd776bfdbfd55dd1cca9e55exls SilentBuilder
2022-01-11 22:46:24e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091xlsHeodo
2022-01-11 22:18:321b07cb00b2a9790fd3d3dbc858112dc7308a0fa920fbc8a8ba019af5ea216752xlsHeodo
2022-01-11 21:38:17244f3b421f675868b3b87f562c2b307e3f4c3b914d67008406a8f9ed0594b4c1xlsSilentBuilder
2022-01-11 21:23:56dc1a568534305e8dd82443bd62f3fefe364de2073558c8237bbe099593714259xlsSilentBuilder
2022-01-11 21:11:54c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7xls Heodo
2022-01-11 20:53:22b5d8116e0b4f01eb2affa09d857d1be4df2e18dd793e4ab0b6ad28e0d5eadc15xlsHeodo
2022-01-11 20:27:28b3a64afe3a1360279c7354909eb0733a15870549ca068a851cb8dc7b672ee168xls SilentBuilder
2022-01-11 19:57:29426fda840765e44250686f1102e902242babe0cea36a756beac6c0757a73c28axls SilentBuilder
2022-01-11 19:26:23a0a6e55d2714273e7c3866776a187cc320e9bfa5086632fc12ed94db2efbfc3dxlsSilentBuilder
2022-01-11 19:18:487b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cxls SilentBuilder
2022-01-11 18:48:3118e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51xlsSilentBuilder
2022-01-11 18:35:20a5a1c304ab3b2351a82da736cf9c022ea2ad1cbff6321b64b0a741b575c8a6c4xls SilentBuilder
2022-01-11 18:02:08e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75xls SilentBuilder
2022-01-11 17:37:121e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1xlsSilentBuilder
2022-01-11 17:29:4614e585c42b502e7e5ba9cd07618751748e748fd0a938c114c51a379de2d1082bxlsSilentBuilder
2022-01-11 17:04:55c5850b16a368ab7c8f2d03cebcc7dd51173a704cdd1d6c105ba43083a40b6063xlsSilentBuilder
2022-01-11 16:53:00788a3d46892b3580cf799d66bb7348a0d50ad1543027c036530fc0fe5135bac5xls SilentBuilder
2022-01-11 16:32:469e3e47f20134301b475d2d5477000f2ff061b7e2ccf7c02aa892d300c3da3b36xls SilentBuilder
2022-01-11 16:21:01b4f4e361680cbe98e26106393beca73acc80418fdae4ab118917b7e8bd9fc917xls Heodo
2022-01-11 15:50:01e72ba4e44af17c551987d6b44ed50a32ee9ef89e049a5ab5524bb1134e807fdbhtml  
2022-01-11 15:46:335b8d0b12d4a393432ef70e1832915b20c0a39b948c524ac301e3ae5f9794b84dxlsSilentBuilder
2022-01-11 15:22:4417832170dc965d40f1a4b7b5abf6dd5f8d131468c82c281388bf6f6967b77490xlsSilentBuilder
2022-01-11 14:56:29d2c48bc93b2b0711be6bafd81a7eeddc944514e110ef2e1014151dac42e8ab62xls SilentBuilder
2022-01-11 14:38:5489224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9xlsSilentBuilder
2022-01-11 14:18:182d88cf677aeabdb77c1e2b34f7bd793635d9c8254af25ad79e8fd14cb2490fcfxls SilentBuilder
2022-01-11 13:56:57536dbda1b94a2895f0cd8c5a95d08b931ddfaaa3ca8a0d476810d6c3488b27f6xls SilentBuilder
2022-01-11 13:49:16f13baa81b2f7abe5a22baaa55d861fa6b6083fde4a8359c2a486386f8a4f2470html  
2022-01-11 13:49:084b62cf1957992336ee9fec25094b8df5b72020ad18bb2bd11c1b43249dc00f4exls SilentBuilder