URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: fx123.xrea.jp
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-12 10:16:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-09-25 21:30:32 160.251.151.224s1004.xrea.comNot listedAS58791 MAINT-JPNIC- JPyes
2022-01-12 10:16:06 150.95.9.224Not listedAS58791 MAINT-JPNIC- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-12 10:16:06http://fx123.xrea.jp/wp-admin/K26536/Offlineemotet ext epoch5 redir-doc xls waga_tw
2022-01-12 10:16:06http://fx123.xrea.jp/wp-admin/K26536/?i=1Offlinedoc emotet ext epoch5 heodo ext sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-13 10:48:31d32a60905cbcf3b82765d7291ede8777aa420c096699a8f848d3417e53158346xlsm Heodo
2022-01-13 09:20:406c5843f31e83acb3be71be737cb15c279df63ad2191db42d1687985925eee1c9xlsm Heodo
2022-01-13 08:34:0088977d27416e992b052f90d09162c6764764f2bdca956efed4b9963104efd75dxlsm Heodo
2022-01-12 21:37:078f99cab09eb9674d602d903701978b39bbe6bf9eb123a358837b44e4076a5e86xlsm Heodo
2022-01-12 18:30:36751860b0793aa0128ca038bf61fd55eef8d6c91e9c6fd876ec3492ba27f03e8exlsm Heodo
2022-01-12 15:01:16ba7c1dc54af2f71c4737c1122c4092af41db3769d6f6883cfcc27636f9f133b0xlsmHeodo
2022-01-12 13:41:47feb79a563fb0b9180b8575e4cadda7ef1cb87b85ab987a569113cc27b1feee34xlsm Heodo
2022-01-12 12:40:40cf829587ffb5a1c3781d3cad3a56024af4c9af07812e7e0ffdabdcd44b984c97xlsmHeodo
2022-01-12 12:24:06edd636c8f738b0cf504e216d9ee701b4d5dc59238f23581ce530df5f8b3c1968xlsm Heodo
2022-01-12 12:05:398679aa6bfcd5e3177948929f4722ebf6ba365309370d3bd101aef94395d428e4xlsm Heodo
2022-01-12 11:43:00ab86bf26ff075b6f59bb540f861c79d56574a790af7bda4cd1c1b3a2bba86c84xlsm Heodo
2022-01-12 11:23:378a6158a2ff4695e06f93b318856526a5ffa730ba8ae4027796d172cf338286e3xlsm  
2022-01-12 11:11:420931df1c8f6f64bb1eed834909d091c56fae86bdef99bc2f0ceb31098b86cf17xlsm  
2022-01-12 10:46:29f005cf1bf27f53cb79db476f4f0e7870b84fd49bfbe6997bf29bb75de459977cxlsm Heodo
2022-01-12 10:16:05382f87f7b2266cc6d3b1e8b5388d60d63b5cfc6030a24b229e850c5fb6524321html  
2022-01-12 10:16:056828ea8aa944ba958a4863701d41c46fbac044a3916242dc9495151fbd977612xlsmHeodo