URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: car4libya.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-27 16:06:04 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-08 16:56:16 204.11.56.48SBL494567AS40034 CONFLUENCE-NETWORK-INC- VGno
2020-12-24 01:03:22 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2020-10-27 16:06:07 31.31.198.107scp80.hosting.reg.ruNot listedAS197695 AS-REGRU- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-27 16:06:07http://car4libya.com/cgi-bin/sDBhPqx/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-27 17:01:05e3fa57c5e24d254e1f737f20f3ce2f2df786f427d74b6a08b7d86c47f0116a62exe Heodo
2020-10-27 16:37:12d8aca34b256b1fd0fb4aaed906d40ed0871eacca3f39f763fdea1d9fa0de3f58exe Heodo
2020-10-27 16:24:40f40200533cec8a16c7185a555ac8944f8db65003fea677859d43a88458518056exe Heodo
2020-10-27 16:06:068feecf1e431013a67d836db43fac50c4374c4989661d4a66f9eb2562bcf6f602exeHeodo