URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: betsdotdestek.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-29 12:54:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-31 19:14:05 89.163.249.221Not listedAS24961 MYLOC-AS- DEno
2020-10-29 12:54:04 172.67.200.99Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-29 12:54:04https://betsdotdestek.com/cgi-bin/esp/Wkf9naDJC...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-29 14:27:1928bac98a17d0c41c279c0e1869b2027e4c0f12c18f2cf2cd1ea9b48e1bbd3adadocHeodo
2020-10-29 14:04:54d824951fa066087d975e4101f588cc0a8fe67b18a5463c70bce2d532ac799b5fdocHeodo
2020-10-29 13:47:19f1d51e59ba0bc3a294abfba9fc97bb554dab1527d5414bfdbd46ce60260b74ccdoc Heodo
2020-10-29 13:07:27e4cd2a6cd5ddb6634b2da0db1a52078c670b59d8bc62fba342adc38d28bec6b3docHeodo
2020-10-29 12:54:0475fc337dd52e7d9cd46cb3a7938551eeefc05a67075a62e6442a0b6501c4fd0adocHeodo