URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: customairdancers.novosigns.com
Domain registrar: n/a
Domain registration date:2005-05-22 21:12:41 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 20:36:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-11 20:36:05 207.45.187.106north.securenet-server.netNot listedAS22878 ASACENET1- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 20:36:05https://customairdancers.novosigns.com/cgi-bin/...Offlinedoc emotet ext epoch5 heodo ext Cryptolaemus1
2022-01-11 20:36:05https://customairdancers.novosigns.com/cgi-bin/...Offlineemotet ext epoch5 redir-doc xls waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 01:19:06663ca3b8545e4e02572b5d348a1f77c7ef30d1810e8adbe25dd699b2cfb1792fxlsm Heodo
2022-01-12 01:00:24b34e6de4f7fc9427651923dbdfab0c34ff83e99f9d44a4bfea838e1b4e59907fxlsm Heodo
2022-01-12 00:27:20b5e8f3567a440978a4203bb8ad88886ed6d4c9c2ca4a599897d7227c56368bd2xlsm Heodo
2022-01-12 00:13:48d193efb518a026a5507a4bb6bc168c2f7922c39ce1bb8fd5553512152cc2b88dxlsm Heodo
2022-01-11 23:55:51d3e6a6a97ad6e4f79e73386e88cddd5b958d0f8745c551837dd366b929671704xlsm Heodo
2022-01-11 23:26:42e06e1cc33f42f59f86b44d17359234628540e287dc10a39ac66ae21449abd380xlsmHeodo
2022-01-11 23:08:51d232986e906c448669c346c5edefc1d51b9224b6d53afd360e4768f9861eafadxlsm Heodo
2022-01-11 22:44:02dd14be16e01e5fe53b7cf8199af830a979dbbbc33593606f3b25d7ea3b32697cxlsm Heodo
2022-01-11 22:14:57b8662d7aff6b2489b65fd6ddc022a5a87c6adb0e1ed1f0286ccd80c0bc11471fxlsm Heodo
2022-01-11 21:39:478ad61be673c186c9cdfb6c6c8d750fbcf80f920d4905742c0ed9d67833026ed7xlsm Heodo
2022-01-11 21:23:4169fdc8b909b3d9e8de4ffafb89dff475c99a4e3ac57eda41c014cea8ee8ddcb6xlsm Heodo
2022-01-11 21:09:148e6f2f4a5b3f21565eb5ebddea133dff53d5904357950842890bc5bbda52ed2fxlsm Heodo
2022-01-11 20:52:40e8aafc15bf0669df883db0e64e8f43f3682a856e74e19e95d9aa6b44aed98ea4xlsmHeodo
2022-01-11 20:36:0454ea8278be35064a8017aefe7f5c1f1497983d965e89621a056edb730b109bdcxlsm  
2022-01-11 20:36:04c522b9e9013459a7936b28890e37c90e8898511259d5a787c4f5d6bbbd93eb1chtml