URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: delfa-test.mk.ua
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 10:01:03 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-21 10:01:05 176.114.5.140s25.thehost.com.uaNot listedAS56485 THEHOST-AS- UAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-21 10:01:05http://delfa-test.mk.ua/wp-admin/O8A64A1/ZX4YG/...Offlinedoc emotet ext epoch3 heodo ext WeNDoR

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-21 13:03:2690828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fdocHeodo
2020-10-21 12:41:45995fab075fc393e1c658b5662d0bf1101044cbd68804263977b0955faf7e044funknown  
2020-10-21 12:25:26c555dc072900eb5e381bf1b8519ef6f3544db1285215e5c20506f33b4a9ae4cdunknown  
2020-10-21 11:50:562a7fcf9bbe90fbb4cc8d2a18d46cd3f492e7bc398f83f7e6923bc377e42f90d6unknown  
2020-10-21 11:23:24ca79466780dfaacfd5d5d4faccf309799841cb68647934e32363466f99877932unknown  
2020-10-21 10:53:08e7e593371e2432b6027bb509db7e21101f1466cfe7ac30a714fb7c110f4562ccunknown  
2020-10-21 10:01:050fb0f9eb73014e90f5345b2b6cb12bb7ca2504c9b0e651eefc0b585946f232aeunknown