URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: abclash.zlygu.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-11 23:45:04 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-11 23:45:07 103.120.225.186Not listedAS4837 CHINA169-Backbone- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-11 23:45:07http://abclash.zlygu.com/wp-content/Overview/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-12 16:43:40272b2ee94e735c0b96219372ae505aa8689e9790ff6390568311fe3eb01a9f2fdocHeodo
2020-08-12 16:25:33c8a786dc04983454baecf5cf019aca018b4616625ced2d911f1ef8ae0f350b92docHeodo
2020-08-12 15:54:17b87ff30cc3663efbc1f5415e7edd1849c8c42d44232ea54e2bf7849ad5fe122cdocHeodo
2020-08-12 14:22:19307363fd029fcc54ed657d3f51f24d9e8f3f7fa7189297216ec7a3a514d1197fdocHeodo
2020-08-12 14:05:262c99381fa134d8121f52b07a62cf94574cd977c2662a4087f18b2f5960370005docHeodo
2020-08-12 12:14:178133ad23a95674ac43c254256076e1571b6ac10c7fa712df1a0a3fc9054f2093docHeodo
2020-08-12 10:44:21e9b11c739e5d0a771cb4efdc41e3d084460fa975e42a309294ab185eb2836728docHeodo
2020-08-12 10:20:42dbbcb02ce1775cef0bf8d1ccdcbf4789d5936dc08b63afaa7ca81e20aa03a597docHeodo
2020-08-12 10:00:409ec7ef1bc0701307cd1c1ddc9a252a989e724abc0705fec55d8bceefc7ffd087docHeodo
2020-08-12 09:30:39265373b64df48b69c520486d767efa8c028ec29d4b7cfaba05e0459400ad0b2edocHeodo
2020-08-12 09:06:02408bd6525ea4e38ffe39a42a4c24c314099dff289a0cf7ff621c7f171c63792adocHeodo
2020-08-12 08:30:40b00309dc3091f93c13fa36bd5d5fb4f1d080f70ab1eabe94d84eb8423dc3d5dbdocHeodo
2020-08-12 08:13:0281c27d10e37bd700d8cee11eba8d01d2bda91b7743083fa7a4e51f3f169ef0c5docHeodo
2020-08-12 07:53:391e1197d27bc4e2c81bf36570d41052b3f74d24df43ce0250b2d53d7b2269c20bdocHeodo
2020-08-12 07:33:55fe14ae5d76ac1ccafc67f474efe315000dadae344444a44c9200e04e94ebbdaddocHeodo
2020-08-12 06:45:02025046a10693eb1c9dca8e64fa2dc55f1ba16ff9c6650493205e2c3af827e1dcdocHeodo
2020-08-12 05:58:458e22bd7e1069b711e14984376aa66b7994d91748a87570e44d30cc4437ab8f79docHeodo
2020-08-12 05:42:41c978e204a4343d19a9b1df57379618a391455fe0f0fd17e49fcb670670c4241cdocHeodo
2020-08-12 05:25:496f973501cc2dece992aa2f959f8e352e424e96f06abb300b4bed8bcf2ab4bf34docHeodo
2020-08-12 05:10:121d2096f4adcba717670858b98912615f7bc86bd95ef6b3117901aa4ae6383d4ddocHeodo
2020-08-12 04:49:46f9f228e552c3971983d4b5909776c052df083b9b41f65f764ceba0dc9d6219e7docHeodo
2020-08-12 04:32:10e95c19b3173d0c69d60efb950859b2ffd3020235efd6c47ffebddf950a0edf52docHeodo
2020-08-12 04:16:3129a8f854081e5f20b6709851863472cd33a1863fbed4867153edf6fcc5e86dc8docHeodo
2020-08-12 02:45:347575d9ebd2153fdfbf4c1626ec4769e8cdef40ea8e2990670f1cc5cba71a2e7edocHeodo
2020-08-12 02:29:414c3eddd6a41f348b80609e91f83e3a9e22818758105ce3db1de70777baeae682docHeodo
2020-08-12 00:58:15358176ae69d49cbdc29ce5f8965efe9952253949970d9de4e8f09f46c488e6ecdocHeodo
2020-08-12 00:43:125d38e73c8e461773d7bd09fd69760d3e0335e51cd3df39676a4c2af22343c43cdocHeodo
2020-08-12 00:28:28e4d1deaefa7f905c5ce7490867ae09ff2d50fdf4162f102e276653c1c46eeab6docHeodo
2020-08-11 23:45:061f90ccc8d181cc6f56b3c906d08d6da99f0b70301870c86084d8899983b9238adocHeodo