URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: detafa.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-05-06 07:05:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-06 07:05:09 134.73.55.67Not listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-05-06 07:05:11http://detafa.com/cps/nass_original.exeOfflineexe Formbook ext Jouliok
2020-05-06 07:05:09http://detafa.com/cps/nass.exeOfflineexe Formbook ext Jouliok

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-05-19 10:22:21dbfa283c5c2952606e5320013691aa62f481cd21b9cdfbb0e2c15272d90bff4aexe Formbook
2020-05-18 14:02:483f2f3a14735554ed3aff984872c82525605f9574583d6e213219d6f3c0132cd5exe Formbook
2020-05-18 09:02:55b8ee3458736fa73672b43a4c55e136bafc48b215dcb89dac28b5865ab59fc99cexeFormbook
2020-05-17 09:16:406d15e8c5e474afa9a5a86223cb28090ed152659e8a225e55470317ec99dddc32exe Formbook
2020-05-15 12:57:422dd5454985f9510ea6428ac4c0bc6874640edea1a83023a35a536da1d9697a49exe Formbook
2020-05-15 07:16:0720da0baacd7e41c7b185d2d4b386079893912fb569f6322999156fdbbe6bbc77exe FormBook
2020-05-14 10:19:501fe8a907a2f2dd25379b8f48698f397ba03e5572a633c72c958c063704a8adfdexe Formbook
2020-05-14 06:01:435df06b5d632b57e5325fa1e9c3be4f5e80c790ddfb9893cab9b7802b7f17ce41exe FormBook
2020-05-13 10:49:28fbb64fdcbdbf49f5563045ace82690efb50d794931f8407c414384ab7d29fe5bexeFormBook
2020-05-13 07:07:49d949f8296ac98de451f12316debf06b71708d96d3e4b1b4aea77bee6338e0a5bexe Formbook
2020-05-11 11:34:392227a53cf9f5c999b87d560575a9328cec0e53a3e06eb8eee9944c1dd2e4f4caexe FormBook
2020-05-10 17:12:26ed3318102d772c4dcecfb1e10f37cfd3fdcbaff1d340ba9c2bc5dcfe6383f339exe FormBook
2020-05-08 08:18:26b045411ef0fdfc078364082d05e8d3a558a3d5f7d238f5904e19da753eed3967exe Formbook
2020-05-07 05:21:132715244abebbb8a1f58679bf1734221c652a61c7720edf7400a58c7721f54076exe FormBook
2020-05-06 16:11:1461e169cb08c5e3b163370cd992574347625e887eca583922412ddfaed2d6bd10exeFormBook
2020-05-06 07:57:384923037fb58a4491f08c85e0cf38a74d92dd36860932814170dc942a031bad2fexeFormBook
2020-05-06 07:05:07262c1d496f71838d2fc7b82f7d0fd1544bfb9316f33bab04df69b473db2cefdeexeFormBook