URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: farsokim.de
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2018-06-20 11:42:01 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-07 22:23:41 162.55.40.124static.124.40.55.162.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes
2025-04-27 13:43:53 185.53.177.50Not listedAS61969 TEAMINTERNET-AS- DEno
2019-04-01 05:32:46 185.53.179.6Not listedAS61969 TEAMINTERNET-AS- DEno
2019-04-05 06:39:46 185.53.178.9Not listedAS61969 TEAMINTERNET-AS- DEno
2019-06-12 16:25:06 185.53.179.7Not listedAS61969 TEAMINTERNET-AS- DEno
2019-02-07 12:39:59 91.195.240.126Not listedAS47846 SEDO-AS- DEno
2019-02-01 08:15:12 72.52.4.119a72-52-4-119.deploy.static.akamaitechnologies.comNot listedAS213120 PROLEXIC-IP-PROTECT- USno
2019-02-01 08:46:49 91.195.240.240Not listedAS47846 SEDO-AS- DEno
2018-12-26 22:49:48 46.4.217.114static.114.217.4.46.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno
2018-06-20 11:42:03 91.121.86.137brzeski.netNot listedAS16276 OVH- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2018-10-17 11:47:03http://farsokim.de/pim/vipp.exeOfflineexe Pony ext zbetcheckin
2018-10-17 11:41:04http://farsokim.de/pim/ucca.exeOfflineexe Pony ext zbetcheckin
2018-10-10 11:15:03http://farsokim.de/pim/fttp.exeOfflinePony ext _nt1
2018-10-10 09:16:02http://farsokim.de/pim/avg.exeOfflinePony ext _nt1
2018-06-20 11:42:08http://farsokim.de/ict/rose/order30495.exeOfflineexe Loki ext oppimaniac
2018-06-20 11:42:07http://farsokim.de/ict/rose/S-order433.exeOfflineexe Formbook ext Loki ext oppimaniac
2018-06-20 11:42:07http://farsokim.de/ict/rose/Calculator.jpegOfflineexe oppimaniac
2018-06-20 11:42:06http://farsokim.de/ict/rose/b-order.exeOfflineexe Formbook ext Loki ext oppimaniac
2018-06-20 11:42:05http://farsokim.de/ict/rose/offer-6A4E3F.pdf.exeOfflineexe Loki ext Pony ext oppimaniac
2018-06-20 11:42:04http://farsokim.de/ict/rose/offerorder.exeOfflineexe Loki ext oppimaniac
2018-06-20 11:42:03http://farsokim.de/ict/rose/order433.exeOfflineexe Loki ext Pony ext oppimaniac

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2018-06-20 11:42:070993eee8eef5efee387f7940d2682ded81d883e59a529a531985812e50e43d3bexe