URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: dadashuo.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-12-23 00:26:06 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-04 03:10:41 156.226.102.132Not listedAS135097 MYCLOUD-AS-AP- HKyes
2025-04-27 09:28:17 154.197.232.244Not listedAS135097 MYCLOUD-AS-AP- SCno
2021-07-17 09:01:11 176.113.71.81176.113.71.81.static.xtom.comNot listedAS8888 XTOM- DEno
2021-07-13 16:54:03 154.204.28.35Not listedAS35916 MULTA-ASN1- HKno
2021-06-21 03:01:30 154.204.27.135Not listedAS9294 GNETINC-AS-AP- HKno
2021-05-26 17:53:41 176.113.69.89176.113.69.89.static.xtom.comNot listedAS43357 OWL- EEno
2021-05-02 23:11:43 176.113.69.36176.113.69.36.static.xtom.comNot listedAS43357 OWL- EEno
2021-02-07 23:03:05 45.134.82.218Not listedAS6134 XNNET- HKno
2020-12-23 00:26:08 45.131.179.26Not listedAS6134 XNNET- HKno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-12-23 00:26:08http://dadashuo.com/wp-content/ocPUw2Sqj28961Uh...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-12-23 01:01:271a0263e1f86a9148e3b7434c12cc232b3a3c92df63c0aa48641c627e87949106docHeodo
2020-12-23 00:26:08b6a4c5fd2aa2119a83b7372ac02aa65feae5a7d083a93656c4a437dd865a447fdocHeodo