URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: buarf.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-20 17:49:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-02-14 07:26:10 34.102.136.180180.136.102.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-01-20 17:49:04 160.153.137.163163.137.153.160.host.secureserver.netNot listedAS398787 GO-DADDY-COM-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-20 17:49:04http://buarf.com/vcds-throttle-w4z41/pqqn/Offlineemotet ext epoch3 exe heodo ext waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-20 21:34:2203ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323dllHeodo
2021-01-20 21:25:35311baf100b99a710f1779342f74a3a74f47434f31ddefaf593ec83155f6f79e1dll Heodo
2021-01-20 21:08:27b839429d88949068bf95af645882e00afa4c454b9a0860b98f936bd3501ac7f4dll Heodo
2021-01-20 20:58:2249f1dbabf84af6358d9804e0b0e6e2aa8ebfe244dcb149a1dfc06d5fab35355fdll Heodo
2021-01-20 20:45:085fcf00dad1f99536e5536116e8e7173bdef1216e85cf853468df97b2b4dace81dll Heodo
2021-01-20 20:38:3167f924debacf91276532adb632f3a3caaaec91e9daae1c5de5a41b50ee7088d5dll Heodo
2021-01-20 20:20:4013e60cbf885aa49255cf3fbb58d7451df2d7da1997b91e03572b6a0af8fe6d13dll Heodo
2021-01-20 20:12:14785ed53d044bf0ce799dad0cc5345a656827072e5767227741d9325362a584d0dll Heodo
2021-01-20 19:54:56a57d2d1085877bbbbbf0d81ddcf6e2fd09fa98dc7d16e832318bf09a938ec0dfdll Heodo
2021-01-20 19:35:042045a27a67f6a09b27ba9f86bc956f07c0c0c5138f9e2a5aba935684b075db9bdll Heodo
2021-01-20 19:29:016f73bed854115c0f6760454609d5324030e77cf84ac8dafbc236507803b459acdll Heodo
2021-01-20 19:12:108e8b1a450cf16be8b9a7a5e8b90a95acd912bb3283188ebf9d49b0213771d85ddll Heodo
2021-01-20 18:59:155e4ac739cc9e1332eee4c0e7eb6e8df09e377972605aa1dc4c7c0b3b14b5301ddll Heodo
2021-01-20 18:39:190a9f4fef6d8941323c54343908aad4e46b583e1aa37c958c32ed5eb0b89b2f86dll Heodo
2021-01-20 18:32:031002669946903bdd0ca592e1b62a426bf347bad9694542f322db036656228de0dll Heodo
2021-01-20 18:16:37b5c390758ba75e7b9fb27d8c0ec9496be397c75e404f789538334697af574058dll Heodo
2021-01-20 18:06:096af6c0ed0ac6d19211dacce93e49c8db126951b46723fc2b9820fb4daef86629dll Heodo
2021-01-20 17:54:33e115d9d5b0ae7dd371fb0aa64f31a3f870453ff34958e5c607a7589ab2b31bdadll Heodo
2021-01-20 17:49:0459be0cdd183b76e73dcb069db3ed7279183ea3fc77afb7df3fbd7c75f5694d25dll Heodo