URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cl5.platsandgo.com
Domain registrar:OVH -
Domain registration date:2020-05-05 11:06:17 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 20:25:04 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-11 20:25:05 92.222.139.190cluster028.hosting.ovh.netNot listedAS16276 OVH- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 20:28:09http://cl5.platsandgo.com/wp-admin/9H/?name=CVS...Offlineemotet ext epoch4 redir-doc Cryptolaemus1
2022-01-11 20:25:10http://cl5.platsandgo.com/wp-admin/9H/Offlineemotet ext epoch4 redir-doc xls waga_tw
2022-01-11 20:25:05http://cl5.platsandgo.com/wp-admin/9H/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 04:54:18aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdxlsHeodo
2022-01-12 04:29:48ab506a8e25b64558a0069af7f78035c4ae3848d8873a5ddd3542d01d2e195565xlsHeodo
2022-01-12 04:06:22e58cd1fc646d37b9fd8040d9f7f4110bb07cbdadb1f5dd4a55413acacd33807dxlsSilentBuilder
2022-01-12 03:42:0348d83d3b6c7ddfcbf30ed8ebe2feb9bc8b5c97dbec16fdbbec64d120181f94a3xls SilentBuilder
2022-01-12 03:16:4861dacefdd04bb8f3dad303b70fe5f77e38e3a57632ba2b9b136e00dd94f7ed32xlsSilentBuilder
2022-01-12 02:40:28046d125d4eaf4ae30ad4a794405fd7c905b58db18824dfbe24dff1cd4cfd13b6xls SilentBuilder
2022-01-12 02:12:27769ecd4d91e53cc734ede1b06a3935096e838020e44061032964dd769dda3968xlsSilentBuilder
2022-01-12 01:57:2229bd3f3218b35ec402cc8c174823b00c2f26b30556c45f2158d175895f9d40c0xlsHeodo
2022-01-12 01:28:03532105c51f0f4b68350191b68f17d6226112e97f273af215511a517604a1770exlsSilentBuilder
2022-01-12 01:02:139d277bf6e9b937c6b9d79db16b78f65ef5346b79c5c68fd3fda71a4e18171fe7xls SilentBuilder
2022-01-12 00:29:52f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feeaxls SilentBuilder
2022-01-12 00:08:39f710943ccdadad818f80e208b3ea05bb57523b5ca7ff2e9647abe730a65afe5fxls SilentBuilder
2022-01-11 23:49:125dd8cf32347063a7b6b80c824526d1f58a3b8c99344eaea74dad15d687395f64xlsSilentBuilder
2022-01-11 23:17:56429e0de91bc404f5fc886f0618177f5bc49fe0da3940e98426c5d5cd8aed57cfxlsHeodo
2022-01-11 23:09:525c5fd037c414e33a6538da72a5ea4ae89c8dac15b396b6a10e8504a0b5a7ee75xlsHeodo
2022-01-11 22:40:20cd8e0110b182d3afd4d91cc9be83efb4de17b54e76e93d861acbd9e981906fb0xlsSilentBuilder
2022-01-11 22:19:061b07cb00b2a9790fd3d3dbc858112dc7308a0fa920fbc8a8ba019af5ea216752xlsHeodo
2022-01-11 21:38:30244f3b421f675868b3b87f562c2b307e3f4c3b914d67008406a8f9ed0594b4c1xlsSilentBuilder
2022-01-11 21:29:309ade9daf48cb63c929cd8e7ec03ac77ed41d362efaa79453d0eda4553747c404xlsSilentBuilder
2022-01-11 21:09:21c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7xls Heodo
2022-01-11 20:56:551224a3bcb32b16ac401374219c7e304bcfd5eba23875426fdbb6bd06345e9e9dxlsSilentBuilder
2022-01-11 20:28:0971c330e812adc3469c5ad9eec6c8d1621df5b40e181ea95271e30226a67e7145html  
2022-01-11 20:25:1071c330e812adc3469c5ad9eec6c8d1621df5b40e181ea95271e30226a67e7145html  
2022-01-11 20:25:050dec37edf7d179a139b89569d030dc83a715e5d9a945d9dedc410c3fcdd09125xls SilentBuilder