URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: dhsh.com.ar
Domain registrar:NIC Argentina -
Domain registration date:2016-12-17 17:44:38 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-06-24 09:02:04 UTC
Total malware sites :1
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-20 04:55:14 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2022-11-20 04:55:14 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2022-09-18 01:07:27 104.21.87.34Not listedAS13335 CLOUDFLARENETn/ano
2022-09-18 01:07:27 172.67.140.114Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.112.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.16.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.32.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.48.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.64.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 21:24:24 104.21.80.1SBL681411AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-06-24 09:02:12https://dhsh.com.ar/wp-admin/H38msg/Offlinedll emotet ext epoch4 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-06-24 12:52:5208e398e1bd22f220d6f3255c50f73b6a3588bfb8f973b39d70b828ca62179f6fdll Heodo
2022-06-24 12:38:16cd03020eb6c62801bf7a76711a50f12af7fbef9cf707203d2f2690e4c41e0e05dll Heodo
2022-06-24 12:26:43b45ce784cee70ec9be16a76468480abac1655f7bf03bdc05d3fd8c34b6365344dll Heodo
2022-06-24 12:18:4140d9ee9e8414bab759dd1e6042b6cd09c57aac919a59e76a4d0aec7aee654c8cdll Heodo
2022-06-24 12:01:263defb424a6168aedfc8cba3d3c25f2f3d1dd12dc75ba98be063f03d778acf3b3dll Heodo
2022-06-24 11:56:1169c4dcfda5f6e17276bb99985cf9bcb7f2a5e694348941bb3c3a4fe30c156fd6dll Heodo
2022-06-24 11:46:358f2fd684a65d90969fbb41fdd51ca0c9ecf58c6c5ec4b440a799fad07a4d486ddll Heodo
2022-06-24 11:34:16d9d0ec1f5fbe646a6f775d845caf9c648f1029054c95ec9413219e812f5dc6f2dll Heodo
2022-06-24 11:19:5035fee41dcffbe18b83b887a0747156f1ecddcada547f110eb6e2a969e016d507dll Heodo
2022-06-24 11:04:0383b4a5b182da95839294497a1c768785e1e12deb7af416614fa2680cc6c48d5bdll Heodo
2022-06-24 10:44:321836abb90fb7d95256caa37d504d7e632b934bc7eccb42274937d45e80f76c2ddll Heodo
2022-06-24 10:30:245ae2ffdc8296c4a97a507c29684ea4e3a078df8ddb3fe7b88a0fe5c7732eb6bbdll Heodo
2022-06-24 10:11:500fda6907dbc1a01f870e564e16afa8b799706f57663401a680bc316e5bfef714dll Heodo
2022-06-24 10:05:15ede987c4ec7cea89d61ca23932cf239ecc0fa346e25c875be9ac041b118736f2dll Heodo
2022-06-24 09:47:5857ff1082561531214499878a857744a975d1e8803eec19142b1b58496745bfdbdll Heodo
2022-06-24 09:37:56e882c3edfac56d5e7333ea11e513510cecdeb044cc52b496d43bb2d1a83ab991dll Heodo
2022-06-24 09:15:4855cd3cba88631fb115cc00b71a33ef3821379ac2a25c060e2bd33da0e60e5714dllHeodo
2022-06-24 09:02:12655502d2be60c76507e9c26237a439323de8d219418bbd16ab9096592d918bb7dllHeodo