URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: buyfon.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-10-23 15:47:06 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-10-23 15:47:17 89.39.208.40cl38.parsblog.comNot listedAS204213 netmihan- IRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-01-25 19:02:48https://buyfon.ir/1vnyk/OfflineTA577 TR k3dg3
2023-11-27 16:39:45http://buyfon.ir/nail/OfflineIcedID ext TR k3dg3
2023-11-27 16:39:25https://buyfon.ir/nail/OfflineIcedID ext TR k3dg3
2023-11-17 19:16:25https://buyfon.ir/mu/OfflinePikabot TR k3dg3
2023-11-17 19:14:21http://buyfon.ir/mu/OfflinePikabot TR k3dg3
2023-10-24 17:47:03https://buyfon.ir/ipo/OfflinePikabot TA577 TR k3dg3
2023-10-24 17:46:29http://buyfon.ir/atvOfflinePikabot TA577 TR k3dg3
2023-10-23 15:47:17https://buyfon.ir/atv/OfflineTA577 TR k3dg3

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-26 19:16:0918785530de0c06d99d817d29d0785470ae108d05f7bc2db218b00d2185ae50afzip 
2024-01-26 07:15:54ee82a6e34b7b605973a87a488664317ca33467f0070bc9b578eae25079fdc0d7zip  
2024-01-25 19:12:29cb324238988a58e67d5dcc079c3209738bb55c78f346a6cf4e3e2ddccc311c83zip  
2024-01-25 19:02:4729a7b10f202a5f80cbbad32ce46528cf373b141bb13fa569435af484976d8df4zip  
2023-11-28 05:03:00bfd23843146c6595ef03fcc1cbec42eb89073ff23d4d4af9e09e049349fc6f21unknown IcedID
2023-11-27 16:59:14358e0b3ff48d118c2a9e981a7e631ba2251073ed808b9a63980eaf45cb9e9f13unknown IcedID
2023-11-27 16:40:32d7e1833733bc57a8bc64b99f40ac7495f82018e58c89c81b68fef50780b10341unknown IcedID
2023-11-27 16:39:4452aab7528ff4fe7d78f08d39ee41d0053e3d054d09c37f1a05fe7aab5db2b34cunknown IcedID
2023-11-27 16:39:2567beea7775ba05b83a19de5a5cb248169885dae3ef5d92f86c194d6c7190952dunknown IcedID
2023-11-18 20:15:3775d381be3e660425f60fb20dc314191d881ce11e9428c9c09a7b5b1a1c3a4088js  
2023-11-18 19:20:39fd8de97f0ca39c4ee71694f52015088a861c8f163bd2773d71766f8ff3ea7e20js  
2023-11-18 08:12:58d31bac9a04da732e7e111710d2eef81ad936f0456b20d7edfbe6ff3ae965dcb7js  
2023-11-18 07:18:31647a227a527e68065a0f9a22bc6030fcf0a8dee21ebd088feaf8a56b79f5f5f2js  
2023-11-17 20:11:00585313b4d910bab26d386bada85700279dc99d91a79316753a38e948f88b3371js  
2023-11-17 19:17:205c940a5349b2a9f5b6c05d8b0b0167fb1748d44d80979f5e3dc91d04f627e2afjs  
2023-11-17 19:16:25490923f506debc8e9ef81ecdf85fdf46ffad8e37d66391c7318c316a8f7ea235js  
2023-11-17 19:14:215423d5afdf67b983d681b026659e01b3f62584fb84b04d7ccb0850df1a6c6215js  
2023-10-24 18:28:535b42cbe6a2a03af9ef79926f297fc3c331ecca054c21f66935a2c5682cb4b845zip  
2023-10-24 18:21:2810528bcc6673f56de44bcbeb758adb34f5ed427590d7383d9c176226362e8f20zip  
2023-10-24 17:47:0391939c349b02c1927c4f1d2f313426a573ddb7d8c929c9f41f6b99f3bc348d78zip  
2023-10-24 05:49:27e3e5cb7b1aed8f995bfe116368df40b8afc08983a391c0bf8146e75b20555dcdzip  
2023-10-23 17:46:2942d9f82472c3fa99f7a8b2182b2856d06e7ba4037e6fe15af8afaae05761c107zip  
2023-10-23 15:47:16a34b7abf596d9f147a480d60672987d7b733188da6367699913b6c5ef08fea31zip