URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: fws.demo9lec.co.za
Domain registrar: n/a
Domain registration date:2021-04-01 08:09:35 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 15:14:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-11 15:14:06 129.232.136.231dedi703.jnb3.host-h.netNot listedAS37153 xneelo- ZAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 15:14:06http://fws.demo9lec.co.za/b/d/Offlineemotet ext epoch4 redir-doc xls sugimu_sec
2022-01-11 15:14:06http://fws.demo9lec.co.za/b/d/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 00:11:55034eaef52f3dc5154e7a94121703ea759fd19784df604e48c8e73ff4fa06cfdaxlsHeodo
2022-01-11 23:47:5866f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6xls SilentBuilder
2022-01-11 23:22:41b5207887a27a42330a6b8e863e0550008a6375de1f4c9c6c0edcc7a9bb6d548fxlsSilentBuilder
2022-01-11 23:00:46207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349xlsSilentBuilder
2022-01-11 22:35:510174c6534f42113ca8854a6ae91e267fb1915bb32b5760b52bbb551aa1580da2xls Heodo
2022-01-11 22:19:2914222deeec10d32091a2947e045833bd25c041a662f4090df26e50381cf922c6xls Heodo
2022-01-11 21:38:18244f3b421f675868b3b87f562c2b307e3f4c3b914d67008406a8f9ed0594b4c1xlsSilentBuilder
2022-01-11 21:31:199ade9daf48cb63c929cd8e7ec03ac77ed41d362efaa79453d0eda4553747c404xlsSilentBuilder
2022-01-11 21:09:4477d7199bee787fb17ba47e4461be479b626921734ac55b7b76d42531c3b1a211xlsSilentBuilder
2022-01-11 20:49:56fd3087fa953ec989caff35845ec2bc3cc41303ac26e0f0d0b8e25a325fee3a29xlsSilentBuilder
2022-01-11 20:28:260dec37edf7d179a139b89569d030dc83a715e5d9a945d9dedc410c3fcdd09125xls SilentBuilder
2022-01-11 19:59:23fa034a838fb84b119629b49d3a9fc672aea0004d361e94548bdfc5153f761c50xls Heodo
2022-01-11 19:32:11e8ada03261f05e1c91d784bf58d10322d3765c686bb4a52278362e0e62288d1bxls SilentBuilder
2022-01-11 19:17:477b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cxls SilentBuilder
2022-01-11 18:41:4618e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51xlsSilentBuilder
2022-01-11 18:27:2260fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440axls SilentBuilder
2022-01-11 18:01:11e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75xls SilentBuilder
2022-01-11 17:44:441e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1xlsSilentBuilder
2022-01-11 17:31:3914e585c42b502e7e5ba9cd07618751748e748fd0a938c114c51a379de2d1082bxlsSilentBuilder
2022-01-11 17:05:56659c21119c192bd5c4c698d0e9c0ef6c5d0ed38bf40907318ccbc4dece45ec76xlsSilentBuilder
2022-01-11 16:46:511cdf6133fd1d4138849b8f2b29f199d90ccce54c369b74a88a14e8329e1051c3xlsHeodo
2022-01-11 16:34:039e3e47f20134301b475d2d5477000f2ff061b7e2ccf7c02aa892d300c3da3b36xls SilentBuilder
2022-01-11 16:18:43071d6c9a40d6721f41c7064edb52f46d766703ea2e9bbe033939b6d60f24604bxlsHeodo
2022-01-11 15:53:12a262302684a8c524a1f8740d028da349026bb9462f2d5b9c7753fdba318132c3html  
2022-01-11 15:41:505b8d0b12d4a393432ef70e1832915b20c0a39b948c524ac301e3ae5f9794b84dxlsSilentBuilder
2022-01-11 15:14:063a3a5f5444557caa3c86b58560956c0a0452818a2349ef7328bb8c948e36d465xls Heodo
2022-01-11 15:14:052e66f6646d6552d0d3cdcd106a2993f04b346a04f455d847807b16fd685925b0html