URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: everydayhaat.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-15 09:40:33 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-15 12:45:49 104.21.76.42Not listedAS13335 CLOUDFLARENETn/ano
2020-09-15 09:40:36 172.67.186.157Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-15 09:40:36https://everydayhaat.com/au2ug/2ONEB9AOP6/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-15 10:14:08558ef3e71171df1cc1d2134b37fd6ce4622038c96145bd61a45e43044e9cb101docHeodo
2020-09-15 09:46:43cbe6e83ec78b4a36eee9c7843c21aaeea59a00df4f8981b870bddd58f1d9a080docHeodo
2020-09-15 09:40:35f46261b1578f7b44ac63d3edd2f32da762c4927378be531a0a73a4207beebb4bdocHeodo