URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: foundlity.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-12 05:20:24 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-12 05:20:26 85.187.128.32sg1-ss14.a2hosting.comNot listedAS55293 A2HOSTING- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-12 05:20:26http://foundlity.com/wp-includes/protected-sect...Offlinedoc emotet ext epoch1 heodo ext 0x3rhaul

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-12 09:31:01d4d1da3fe2782cd37f1c53377907c0e25e85f78e24da0a9d14fd2e39af18abb1docHeodo
2020-08-12 07:30:026fdf256f21e609628e4275ea39b9a5dfba92f53f0a9cd924b838b0418e7a7be5docHeodo
2020-08-12 06:45:097c7837406f4a125ee3a129d23771f32eace788283c06a517f0bdfe7dc4f7036cdocHeodo
2020-08-12 05:20:2679c47358c6ca784a93b378478cf157a96b6810484e3fa17d544d8ab047274c17docHeodo