URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: apps.fbmarketingmaster.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-27 00:35:34 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-27 00:35:36 172.67.197.1Not listedAS13335 CLOUDFLARENETn/ano
2020-08-31 18:55:35 172.96.190.155172.96.190.155-static.reverse.arandomserver.comNot listedAS59253 LEASEWEB-APAC-SIN-11- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-27 00:35:36https://apps.fbmarketingmaster.com/ci/Pages/tqC...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-27 01:24:35cade1ffeb7c4023e29d6f908dd96b6ef4f6d21c0a78dfb0728a0b358302e7563docHeodo
2020-08-27 01:06:1455e8bbf2a59f439bf5dc58b7fe2236ab94b9552b4abf1a74ea194498ae32199bdocHeodo
2020-08-27 00:48:45305e0e9a329ac85f97dacf909710fb3ae485af0e09b6ed9022f8a4dc901623e6docHeodo
2020-08-27 00:35:36763a511d6b6e45d6386a286c0da9cc275171965046f20bf30ba106f6dedc740fdocHeodo