URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: aizhanziyuan.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-13 10:17:06 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-24 07:10:28 156.241.86.179Not listedAS135097 MYCLOUD-AS-AP- HKyes
2025-05-18 17:45:21 156.254.157.15Not listedAS142286 HKIDC-AS-AP- HKno
2025-04-27 15:49:21 38.207.31.116Not listedAS174 COGENT-174- USno
2020-08-13 10:17:10 23.224.185.9Not listedAS40065 CNSERVERS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-13 10:17:10http://aizhanziyuan.com/wp-admin/lm/ysjvf4uke4rj/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-13 16:31:50d567a4097feddecd5e5cabcdde2f997521126535222bec36e0514da36a9886b7docHeodo
2020-08-13 16:19:048c8c709e2b7cfd3dce74062f2564bef84cafcc329cbfcafbc2c056c35cc38c50docHeodo
2020-08-13 15:57:375dfe99bdd766418f029d534146438a97818581f989d4b2ebf5f92179344000c0docHeodo
2020-08-13 15:30:440532eadbdda96ceadb7250d379491c1bb64d6d40b96bc71d551268896fd4bdd6docHeodo
2020-08-13 15:09:258a0a74b31fb30ce1a4adbaa3945c4186c7d467268e76b9ca802905b7cf5fa54edocHeodo
2020-08-13 14:54:06479e00f4a39c727821fabea3c681e051bf755f4eb4c10e62f23055ca7f4a9353docHeodo
2020-08-13 14:13:084b99e8df8f724bfea2f32a9274cf4aa0f41b3e57a2b1ec753b17514149c670b2docHeodo
2020-08-13 13:50:5422c4bc8c9ad10df54d22ae6a89c1b937d49982a7b9f6ed54798394dc9033c0cbdocHeodo
2020-08-13 13:24:5344a4e9297c1d0191631e49532aa755b5a7928836c63b7a9f37deb77293cf2ec7docHeodo
2020-08-13 13:03:4209bd7f442749dac84e11577aa507719969f7eac112f256a50e5b9e8d823a3b78docHeodo
2020-08-13 12:48:1279b609ddf074406de181d656544923255389ac44a068ddaeb858e6546d2787f4docHeodo
2020-08-13 12:31:54bedf54726f739f906db66965be55e05516b933ce872264751f3dd48f5b9db8fcdocHeodo
2020-08-13 12:11:1152426d2c2644ab78cd7fbe3a9e0d19acbd34903d9f62d42fe2e999b964e3eea7docHeodo
2020-08-13 11:55:320c4fc99638ce35263569e89011b336bddac6074ea768e3f77d4d6acfda9e3ddedocHeodo
2020-08-13 11:22:49d366a539f2295b53ca4674d4807b866b78979fda3a5d80e006ce2aaf2e1c24c7docHeodo
2020-08-13 10:56:2157077fbea2ccbc5464be5b94b7e01a59f4b28e6658a7a432645380f6413e8a00docHeodo
2020-08-13 10:33:451a457779d9b645e40120f23efa5aef5b0b97308f610fea5a06377c0603636f98docHeodo
2020-08-13 10:17:0817029a443ed547830073ae822771b993282e801600a0a7955da0a9ffdf9a12bfdocHeodo