URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: docs.dochase.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-11-11 18:01:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-29 06:20:19 104.21.71.213Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-29 06:20:19 172.67.171.190Not listedAS13335 CLOUDFLARENETn/ayes
2021-01-17 08:21:10 23.94.150.194wgh22.wghservers.comNot listedAS36352 AS-COLOCROSSING- USno
2020-11-11 18:01:06 176.9.208.67ds2-eude-ss.host.glNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-11-11 18:01:06http://docs.dochase.com/b.exeOfflineCobaltStrike ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-11-12 07:04:5831ea3b1e0792ad42c5127b11d30ada34e5241bfdaf5d6b14860945d3084d4905exeCobaltStrike
2020-11-12 06:10:425431a9302ef3a26a356303fc023cd1407bf4d517ee4589412fef79606879cbceexeCobaltStrike
2020-11-12 05:37:13636072602927954e7b51329968d6afe084bf7554878c158004e8b0bfd5cb1100exeCobaltStrike
2020-11-12 05:08:32070e94ea601c76a96f0b237f76e9747852a6e555bd0c199161a62d28d69c34f7exeCobaltStrike
2020-11-12 04:36:53eb358b418965336bcfb6badb5577ce68cb69fba65f52332af34834ca2b2023d9exeCobaltStrike
2020-11-12 04:01:382ed6caedb9d58087892a4ff2e966f82bcd4e8e2c530aa90fc659c7d61eb327c1exeCobaltStrike
2020-11-12 03:41:2497c5e481b724ddbc7fa39006c19f024f537a8b1e6e02d233b6588d2264dde25fexeCobaltStrike
2020-11-12 02:57:43c1c941403bca68142cc25df9f218bb8877d5a63007260e041dd1bf5db095af3fexeCobaltStrike
2020-11-12 02:10:570d10ff57bd06aeacd5d947019399ff2635a5b42fab0be39014c945a7588826d0exeCobaltStrike
2020-11-12 01:51:486515daf821f1ba10e5de6f707423f28f48cc80149a44bbfc3331fe24b9a2c3ecexeCobaltStrike
2020-11-12 01:31:01fe64ad3b5e6c425000bcab6e4c997560d4d325d2191062b26403b0a49cf53898exeCobaltStrike
2020-11-12 01:05:18642bf0c02eef2b88a4292b09022f6068bedb4a1e3870249e7840dd3851222278exeCobaltStrike
2020-11-12 00:11:234aca4ba4e12e952c9eefb7d5554a806dcd5a572d1ddcf054251e4c1919e6fa74exeCobaltStrike
2020-11-11 23:39:20a50af9fb8e00f47b558e2f8e25de4aea67227f0b4120eaaacff3215af2c5258eexeCobaltStrike
2020-11-11 23:04:2827f9ac6bd41284e86f0199eba0e1d7ad3703d04e095b0c8ae8ccf850b32365acexeCobaltStrike
2020-11-11 22:27:2610f982f456d963b82655b03b59a4ea4877832899067e14c96990b809c5767b72exeCobaltStrike
2020-11-11 21:46:55e46873324ee44e0f0b2b3ea745abe5f1b7875189bc04d9abc86330620ab97c51exeCobaltStrike
2020-11-11 21:01:299db36c4d4f578a68ddbabcf25a2a3ba0a0e0cce2847f62da9ac4f8b5682ab745exeCobaltStrike
2020-11-11 20:38:33dbcb927d98301d49758b5a6e419e618acb92ecef3bef20c99374f5fde154eb1dexeCobaltStrike
2020-11-11 20:08:2406a2955307b8c26009b441754df7d0c94d3a913b0644a3c8779f592648dd1a0cexeCobaltStrike
2020-11-11 19:22:140adcf0b5e5216f4ac6fe82d4e2c7e351845cfaf6717552aaa0c80d643ee9f2eeexeCobaltStrike
2020-11-11 18:31:48777b4ad720e0c2982e161342e3cf77cb755875664f24131018b7df4d853fcd60exeCobaltStrike
2020-11-11 18:01:067566ae70559b61077911e17564dd470be33abcf8e725352f546a731af43e5297exeCobaltStrike