URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ferroconsultora.com.ar
Domain registrar:NIC Argentina -
Domain registration date:2014-10-28 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-29 14:09:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-04-17 15:53:41 200.58.112.97c205.dattaweb.comNot listedAS27823 Dattatec.com- ARyes
2022-03-29 14:09:08 200.58.120.249dtcwin170.dattaweb.comNot listedAS27823 Dattatec.com- ARno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-29 14:09:08http://ferroconsultora.com.ar/cli/3gKSvURXLb/?i=1Offlinedoc emotet ext epoch4 heodo ext Cryptolaemus1
2022-03-29 14:09:08http://ferroconsultora.com.ar/cli/3gKSvURXLb/Offlineemotet ext epoch4 redir-doc Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-11-11 20:48:46a6dc3a7a4834de6a413ac8a868b2a212d18b2d0f967d8771e180db7c60f1103chtml  
2022-04-25 22:23:133bb70fc8139d66e89c6ec264307263846d9d769eb0373f73ed448999ef316d44doc Heodo
2022-04-24 03:10:1994184fa6adf5d10e9bad4bea5ef1a90b5d19b6329a2cac25377b11e6b90de7acdoc Heodo
2022-03-29 14:09:0765cb61155f04597306d3d063ed292605790a5dca2c616422756b23ef4d5c18dfxlsHeodo
2022-03-29 14:09:077b9e621abd983ed4a375b43aefa4d1212bd0b0fba5afaf348857ee728afebc06html