URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: armgroup101.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-12-12 17:42:12 UTC
Total malware sites :1
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-14 07:56:06 103.215.222.14Not listedAS48551 Sindad- IRyes
2025-07-25 03:11:42 185.192.113.215sv4.npco.netNot listedAS60976 POL- IRno
2025-05-28 23:03:28 94.23.162.163ns2.emailverification.infoNot listedAS16276 OVH- DEno
2025-05-18 22:54:21 54.38.220.85ns1.emailverification.infoNot listedAS16276 OVH- FRno
2019-12-12 17:42:13 185.55.225.198sohrab.dnswebhost.comNot listedAS201999 Serverpars- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-12-12 17:42:13http://armgroup101.com/Old1/cpfa/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-12-14 02:59:47181a79a35af190ce05e5bac09e23d8670c247db0b55f465ff2af8c834e984ed6exeHeodo
2019-12-14 01:37:106cf54601213e918f6f70d5d1a394932ba42bf99415392125f57453f38725d1d4exe Heodo
2019-12-13 23:35:072f623751af7cd78659100a3ab30edadd4e3c26039f076e8bba220137f3c0d4c9exe Heodo
2019-12-13 22:29:0721556b2d910de92eee35636dd5e5b04935525ddbc544f2f632ac3b1d5acbeeb6exe Heodo
2019-12-13 20:28:00218a87ca8c818acf90e3e7ee180a7d064d55c10f6c2f172ddaa9941f8c1c9531exe Heodo
2019-12-13 19:17:56a993cb9fa4c615bb7656a88f48e3aabbbab3dc2d851ddccb1b80e987a6e3cfc4exe Heodo
2019-12-13 17:17:07ee27ce622d86fc20b1805c2ad66dd90bd7c235083e17217d38ee292488cb19c5exe Heodo
2019-12-13 15:14:386f65c3773b031f0aa512fa527da8e004a3c9694ae5ad3890ca0c6c791b6a61a9exe Heodo
2019-12-13 14:51:5821d345281902ff2e2f2dd1d335c9f0ce983f0edd7fa6eb03fb5713f736d431a6exe Heodo
2019-12-13 14:01:3611c68ed562aae39ce2caa8c3520826595e24c978f4f01ecd25ba2825db21ab66exe  
2019-12-13 09:59:33d9a7f0ef3140c6ad0759c1fa89c6b387b482945c4b48341070ff3661fea36d07exe Heodo
2019-12-13 08:32:270be549352e264c4aebca790a05294684f11ba46b3260cb20b67cfae925634b4aexe Heodo
2019-12-13 07:18:31e01309bf35de5bb3d967004bb003a5a523d97020234abb34eac14878efa0d68cexe Heodo
2019-12-13 05:17:4638f321e1d7367a1002f53d162279135440272af848efe75a6aab71f299599eb2exe Heodo
2019-12-13 03:25:21a1fc8e140dfd5d46b9bdf53cb516cb2aa2ec84bdb29290b5cfea4bbccadd6326exe Heodo
2019-12-13 02:20:27022c139f821927a8f9180689ce0a0ad1a38763cdf20254eb56b41db0c8bc5b8aexe Heodo
2019-12-13 01:17:21e19158e6d8c78cd831df154b5fb36a779a033925be47374d16f59011617aad64exe Heodo
2019-12-12 23:16:13e4fdad187551a7c662fb384bb6b1688229602f4bfd28f49f5b077261ff45f2f2exe  
2019-12-12 22:20:16cbead8b96feb4f51c39055b2857bc3d57055bcc12d75573dd0c7dc1dca1bd204exe  
2019-12-12 21:24:41d84723b06c9490b9bc0281958d5b80fcad7b3e5158d8782a015cdd44174077c5exe  
2019-12-12 20:27:1499319bc5ce7af601eea33ead35c373c1f9f120f2b20fbc54ed76b4a9742286fbexe Heodo
2019-12-12 19:31:33bc762aed5c64a3d3d4ddbc3406f36cb8cac182f2b40e873df558f391749a8123exe Heodo
2019-12-12 17:42:13b3f8e0e34a15d6319aa7e97dc3dcc726aeabc786fb451171083391ba362361c5exe Heodo