URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: erfankala.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-29 22:23:32 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 00:27:36 45.156.185.106ip-45-156-185-106.hosted-by.parsvds.comNot listedAS208161 parsvds- IRyes
2021-01-11 15:03:05 148.251.66.48server4.dn-server.comNot listedAS24940 HETZNER-AS- DEno
2020-09-29 22:23:33 178.33.212.113sasha.irandns.comNot listedAS16276 OVH- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-29 22:23:33http://erfankala.ir/dup-installer/honbm3/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-30 05:36:048ab2e6cb8892b88bad960fc01887038298cebc93804c11f3bf92624541fd00dedocHeodo
2020-09-30 05:07:28d0ce4cd7cb0a84604bbd7f40f0aa48a2f09e21fb9eb3d4b72d64cf88790f3081docHeodo
2020-09-30 04:37:36e9ea0a15b6b1599685f85932e8f8621ebe49b8a64c3376cb3819d4b9f5b536bedocHeodo
2020-09-30 04:25:4609920ec2c5029cdb6177cee45414e34e9307a6f40548df1ba80385c44cfcc613docHeodo
2020-09-30 04:17:0116570616ac7a29eab86f3d418f18b67750c4deca1c01529454e5f1a591e6fc6ddocHeodo
2020-09-30 03:46:198292af351e1a3422b40ca14a730c4a8c4e65bf1fe1daaa33852934cac3a2d43cdocHeodo
2020-09-30 03:29:58010d313ef5a6680acc6fcdaca0eed3e19f256a23cac861684466d6e7f7138030docHeodo
2020-09-30 03:15:035989ac83f73cf6a5aec06cf124e7ec4ae2f9704193be74a77f2e72d1fac2aba0docHeodo
2020-09-30 02:46:54e2689c227ea6d5424060e6fce6deab414a52c4d27719a2a2f4a2b9eb635d4f9adocHeodo
2020-09-30 02:16:558d0311de9248f3fc0efd38e822a2d51fb26ec893e9cef6a0f81a2c2b2ea62bd6docHeodo
2020-09-30 02:07:5631096733d8d5f5ecff8a6a1f0bbf9b3af3fb5f1e8f0b509b342a38cdb0a01b43docHeodo
2020-09-30 01:45:30020aeaa470dfa7a4e9fc3e8d88db9d7f89b1bd64df67a963467490068a6f3d6ddocHeodo
2020-09-30 01:19:59c23dbe57bf9ad222746ad89939427a3fec7c2b13f26a03922e9450f6d07ea0cddocHeodo
2020-09-30 01:05:035620011cd8bf0acd1f3ecc32958d26a9f38c982b191406bada41f3db5a9250e5docHeodo
2020-09-30 00:31:3475f032ed1b4c5d9738c4ebee1d878f1fe5307cba5c43dc44ce2443a640e7fb2fdocHeodo
2020-09-30 00:17:04c7e94b09a7bf83d363a7949d7aef5bba5516bd5b0e0c149bbd1dc341b9cd5180docHeodo
2020-09-29 23:57:406596f751d97b234516bc66104d96abd644a86657c7c981f245101bb9bba1c004docHeodo
2020-09-29 23:28:30ad21f91ac048eeb669e0a9cc8199225d755cf89a9f5d79d7fb39ef2659f04a9bdocHeodo
2020-09-29 23:08:20fbdacf9e30368d59414b52f459d935964b7833d6d8467bf0eb4ccfa97f71e4d6docHeodo
2020-09-29 22:44:000a9fb69a602d43df0ec8d95c2efc4363bba8536cb03debf2b59c809e88e8f86fdocHeodo
2020-09-29 22:23:33a7bac9b6662da2eb4c3fa6f12c10d790ab6b8ef1735241fcd2a4d35a152a8965docHeodo