URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cfs5.tistory.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-03-08 19:28:04 UTC
Total malware sites :1
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-07-02 02:58:20 121.53.85.3Not listedAS9457 DREAMX-AS- KRyes
2020-07-02 02:58:30 211.249.219.23Not listedAS9457 DREAMX-AS- KRno
2020-07-02 02:58:29 121.53.202.238Not listedAS9457 DREAMX-AS- KRno
2020-07-02 02:58:28 211.231.99.68Not listedAS38099 KAKAO-AS-KR- KRno
2020-07-02 02:58:31 121.53.201.236Not listedAS9457 DREAMX-AS- KRno
2020-07-02 02:58:26 121.53.218.30Not listedAS7625 DAUM-AS- KRno
2020-03-08 19:28:06 113.29.189.156Not listedAS18160 AS18160-AS-KR- KRno
2020-03-08 19:28:06 27.0.237.141Not listedAS38099 KAKAO-AS-KR- KRno
2020-03-08 19:28:06 27.0.236.146Not listedAS38099 KAKAO-AS-KR- KRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-03-08 19:28:06http://cfs5.tistory.com/upload_control/download...Onlineexe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-03-08 19:28:06e335cb38e7d0352ef807f2d531b4f6cc97c8e9b37ff6cda4a545d366d32a4b41exe