URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: elgrasstrav.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-27 00:24:28 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-27 00:24:30 196.40.97.15www94.cpt1.host-h.netNot listedAS37153 xneelo- ZAyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-27 00:24:30http://elgrasstrav.com/yjavw/Scan/aa6kymc9z-2546/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-27 11:55:519665beb44caa8052a76f4a798884ecf129ba1100691fe28ddb20fa9c36892244docHeodo
2020-08-27 11:30:088969e1e9e29920ba44157da474d4851706f1f63a58b7cd36a87845beaea2af9adocHeodo
2020-08-27 11:12:31da824fbeb1aca76e08e78a0e568930de8ef2c71147fcdc20943bf61f59e8a477docHeodo
2020-08-27 10:54:25c48f047235aef5e47fa8fdbe08dc7b9c9bf5625f22e2e5c48bd9cf09dbe31d27docHeodo
2020-08-27 10:37:5802db21d12dc0b5d4da95ae253092f640997129f192be9c9bf0ca6132f5cd7e2edocHeodo
2020-08-27 10:19:521653613e54e13601c4799c80c854d900b5b794b6f042130935272db8d6d1e2dfdocHeodo
2020-08-27 10:02:270abe748102c354778262121f25bd6d445be4c21e6c3d5ea5f11982bbd8e10ecddocHeodo
2020-08-27 09:24:00cbe78f7b605decf53999dc44e92f4b8d9bb13637f7f40d771a04903ad9ec15d4docHeodo
2020-08-27 08:59:5738aa8eabb4d27eeb9f5150b1d2f27b755f88b11df1a1985794f6677e3c1eb827docHeodo
2020-08-27 08:53:103655157b27b8b084443564d11a050740b1e72edf7bb35e9b2cc619eb795c52acdocHeodo
2020-08-27 08:20:49d1ce94995d38fb4478f96585dd2cfa3427899e1d34645aaa4a83f0abd1a25e69docHeodo
2020-08-27 08:00:314875db6cc826948164d8fa9b177fb20066906af4781846eecf82cbe9765a305adocHeodo
2020-08-27 07:47:151e01a8df8f521e0db311144288882290f51f66435f7ef11584a1d8c4166ec7aedocHeodo
2020-08-27 07:29:5708531c896c900816e373957872ce7e55db50203fd681019719dca8fc27882b40docHeodo
2020-08-27 07:11:24982ec1619efb871fbcb238050b05cb55e526b8ea31b8759bde9e20c45ec482b8docHeodo
2020-08-27 04:41:39869da97b04259da0e14dda9364d9575b02fd770b1fe8802f8145372cc503bba7docHeodo
2020-08-27 02:54:00b87a064c66cdd9719e97ee49c21b6435c4f769164c1195b5d14cf15b9dc81a19docHeodo
2020-08-27 02:38:56e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259docHeodo
2020-08-27 02:21:230cbddd5eeb728ba41f56bd3066629b9ad20536c1373057891cc5ea201d70c2d2docHeodo
2020-08-27 01:59:52a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6docHeodo
2020-08-27 01:44:10b27e8c6c5a1f2ca799c9e70469734034437ef96227b7c5394ab56dc4d55ca8b8docHeodo
2020-08-27 01:25:17cade1ffeb7c4023e29d6f908dd96b6ef4f6d21c0a78dfb0728a0b358302e7563docHeodo
2020-08-27 01:05:4955e8bbf2a59f439bf5dc58b7fe2236ab94b9552b4abf1a74ea194498ae32199bdocHeodo
2020-08-27 00:48:47305e0e9a329ac85f97dacf909710fb3ae485af0e09b6ed9022f8a4dc901623e6docHeodo
2020-08-27 00:31:20763a511d6b6e45d6386a286c0da9cc275171965046f20bf30ba106f6dedc740fdocHeodo
2020-08-27 00:24:3085872bed0d68998bd9881149af3ca6af9707697c935b4423674469e0a3150485docHeodo