URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: elektrik51.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-15 16:15:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-28 06:49:43 185.12.92.144lyra.deserv.netNot listedAS210079 EUROBYTE- RUyes
2020-01-15 16:15:07 93.171.221.163Not listedAS51495 AGTS-AS- TMno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-02-03 20:12:10https://elektrik51.ru/wp-admin/paclm/qtji23qvn/Offlinedoc emotet ext epoch2 heodo ext spamhaus
2020-01-21 07:22:06https://elektrik51.ru/wp-admin/balance/yv3yw4xv...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-01-17 22:33:04https://elektrik51.ru/wp-admin/uCIP/Offlinedoc emotet ext epoch3 heodo ext spamhaus
2020-01-15 16:15:07https://elektrik51.ru/wp-admin/open-module/indi...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-02-05 07:15:171c96dc2ca50755af8de45649f800c5bc8afe690dec831035e2c9c004447e2e63docx 
2020-02-05 06:06:534a2206d2d4159ee6156bcae615a5a64d47680fd4a81a731122cb2efaf696e3a5doc  
2020-02-05 05:53:0740f1eaa7af43464dcc9011db3cbb5850b7306e873cb41410fa989b3f24e54812docx Heodo
2020-02-05 04:41:1216f4428608da80852d79b47755bee8fae77793ac1a89079190a004aef7675376docx  
2020-02-05 03:10:22679f8b9176955bad28be27b0fb4e17d959e8ae21f09f00aa516308fed55eb1dddoc  
2020-02-05 01:55:088b5c629465d1e775ff08a64c17e15af3e0abedc77e2718bf8a7a700ed92c6b27docx  
2020-02-05 00:52:0593334a1d8242b60620644d3f16b4ab512e609bf7f63b0ba1dc5c5d2867748f84docx  
2020-02-04 23:21:081a42a36453236c06c4592ff027a3a19d6ea01f10831412618104dac82de16ca1doc Heodo
2020-02-04 23:12:44d47c77d9d0def102dd934260114120e0bd5fd719e88480dda4a53342cc6701e0docx Heodo
2020-02-04 22:03:19e7f9815f92e7cc94121a968c79606d06bac0b134593d51cf2defc641e1f34865docx Heodo
2020-02-04 21:01:164a61bb6feeafc9168711f5de2e6d486132267d88a40ccd5dbeb5b5e41cd77189docx  
2020-02-04 20:28:596cf7056ab0ef95c3e0e7db2e9667532ca55ef9cd4b846c0bf1012328ee62dd7bdocx Heodo
2020-02-04 19:29:1210a4a79ef018d8594156fc6ad3dc14646fad3b07d661af9c687034c39dccf0a4docx Heodo
2020-02-04 18:28:059a488725dd70310efcf93ffb12cdafec6afc75ec136bf91b5e3ecf1cd6ebc3dddoc  
2020-02-04 17:21:5423b5a2d4a45010250ab641363a1188ba35bd619cb0135e3dd3ce645c9504774ddoc  
2020-02-04 16:01:03f98ede027a5dea9db32a00632bbf77d91899875b2271ee9e7ccf7cac0cc2ace8docx Heodo
2020-02-04 14:57:12b6e927546375b3a3421f35d0c399db92beceaaf46b8981207a74ca9cb6782e21doc Heodo
2020-02-04 13:40:39ed6fe435d8858c9022bba057c44d5c167d0e3be265432ec2a6e6e7566a2b14b2doc  
2020-02-03 20:12:0913ebd8cc80fe0d18140b6deec77af3ee048c4ad302fd2e43a804b2aa69529017doc Heodo