URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: docuserver1.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-06-24 01:23:03 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-08-26 20:11:19 81.17.18.194hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-08-27 15:14:50 81.17.18.196hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno
2022-06-12 19:15:54 99.81.40.78ec2-99-81-40-78.eu-west-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- IEno
2021-10-24 22:54:54 66.23.235.114Not listedAS19318 IS-AS-1- USno
2021-06-24 01:23:06 66.45.232.203Not listedAS19318 IS-AS-1- USno
2022-06-12 13:30:08 107.161.23.204parking.namesilo.comNot listedAS3842 RAMNODE- USno
2022-06-12 13:30:08 192.161.187.200unassigned.quadranet.comNot listedAS36352 AS-COLOCROSSING- USno
2022-08-26 20:55:52 192.187.111.219arf.qwiqo.liveNot listedAS33387 NOCIX- USno
2022-08-27 05:28:56 192.187.111.221tyg.qwiqo.liveNot listedAS33387 NOCIX- USno
2022-06-12 13:30:08 209.141.38.71parking.namesilo.comNot listedAS53667 PONYNET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-26 06:39:03http://docuserver1.com/d/write.exeOfflineexe opendir abuse_ch
2021-06-26 06:38:26http://docuserver1.com/d/ngrok.exeOfflineexe opendir abuse_ch
2021-06-26 06:38:07http://docuserver1.com/d/po.jsOfflinejs opendir abuse_ch
2021-06-26 06:38:06http://docuserver1.com/d/info.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-06-26 06:38:05http://docuserver1.com/d/word.htaOfflinehta opendir abuse_ch
2021-06-26 06:38:05http://docuserver1.com/d/word.jsOfflinejs opendir abuse_ch
2021-06-26 06:38:05http://docuserver1.com/d/doc.exeOfflineexe opendir abuse_ch
2021-06-26 06:38:04http://docuserver1.com/d/word.msiOfflinemsi opendir abuse_ch
2021-06-26 06:37:03http://docuserver1.com/d/OCC.docOfflinedoc opendir abuse_ch
2021-06-26 06:37:03http://docuserver1.com/d/OCC.docxOfflinedocx opendir abuse_ch
2021-06-24 06:22:11http://docuserver1.com/d/word.exeOffline32 AgentTesla ext exe RedLineStealer ext zbetcheckin
2021-06-24 06:08:05http://docuserver1.com/word.exeOffline32 AgentTesla ext exe RedLineStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-01 20:52:23888126d0069e6c631531e8f52a5a50a04dc3691b3d3a70e17028e807b2225b72exeRedLineStealer
2021-07-25 22:22:4942b69d127811ca7706dde5099f967a1502a3192cf4e3d4b0b7cf5660959f7d07exeAgentTesla
2021-07-23 08:12:09cc773fa6caca8fd14bc2b054038dcaa627496f233e31c9b51ddc0d7e51d1a79bexeAgentTesla
2021-07-18 20:30:47635764197d1aff622d35d6b6c44a72c8a09b60a55ca465cef868ba428b30b164exeRedLineStealer
2021-06-26 06:39:0345bd87a5803916409a0d824beefafb1faf49d52e0ba9c0e8014e82eaa17e7659exe  
2021-06-26 06:38:2696aa98acfc7b20f08b3fad53f7e3c7ce3d8463d3376e1cc76949b20aa265c403exe 
2021-06-26 06:38:0710f2a027a4d8845cc65d98a0897a56998d4e8a978bc46c0db57c4da7070b5f52unknown 
2021-06-26 06:38:069f2ac60f8370f645f50a08dc1c87c0c6964013c586138942bf457682f1d6eaefexeAgentTesla
2021-06-26 06:38:0510f2a027a4d8845cc65d98a0897a56998d4e8a978bc46c0db57c4da7070b5f52unknown 
2021-06-26 06:38:04cbc33a9a7cc70c2ab98efc7d3480dcc748f39eda03040ff31f783cbb7339abc5msi 
2021-06-26 06:37:03a77d4bea223fefea9372cd1b01aae4f41b8624d1ed4d9e593d212e1f42295b5edoc  
2021-06-26 06:37:0350a90953382c7be06b5fe9c383c9e45db4091870b2b89b294ab679b869bb5afddocx  
2021-06-24 18:50:07fa36827395f1ca463f06226a4e8c49882454ebab18496aa47953e9f332c3f990exeAgentTesla
2021-06-24 18:43:44fa36827395f1ca463f06226a4e8c49882454ebab18496aa47953e9f332c3f990exeAgentTesla
2021-06-24 18:26:448bc6498475ce56e16d23a8feddc2b231f6afe5ef1a25dbbc9338c5854e3fbfadexe RedLineStealer
2021-06-24 13:21:193f2e8fd710205958051a8f03cd6ba8e0595e9a6688b08255ff11af359a135dccexeAgentTesla
2021-06-24 13:15:343f2e8fd710205958051a8f03cd6ba8e0595e9a6688b08255ff11af359a135dccexeAgentTesla
2021-06-24 06:22:11c47a4294b97b5b05ac78f01950d4cf964faf03adf9f0b495c157d09c6f3cf564exeRedLineStealer
2021-06-24 06:08:0500668082deeb1c79ed4a3b9cc93bdcb63a49a67dce5f931c0ec4de660a758334exeRedLineStealer
2021-06-24 01:23:0569858f544bafcbb3e3f32f1584fa4d162cdc44cd9fd05c129044ff081a8becaeexe