URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: getcsr.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 00:58:03 UTC
Total malware sites :1
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-09 07:51:44 13.223.25.84ec2-13-223-25-84.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes
2025-08-09 07:51:44 54.243.117.197ec2-54-243-117-197.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2025-05-28 11:03:46 13.216.111.180ec2-13-216-111-180.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-05-20 20:42:20 52.71.57.184ec2-52-71-57-184.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-05-20 20:42:20 54.209.32.212ec2-54-209-32-212.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-04-29 11:00:39 3.18.7.81ec2-3-18-7-81.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-04-29 11:00:39 3.19.116.195ec2-3-19-116-195.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-05-10 15:37:57 3.94.41.167ec2-3-94-41-167.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-05-10 15:37:57 52.86.6.113ec2-52-86-6-113.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-05-03 17:24:07 3.130.204.160ec2-3-130-204-160.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-21 00:58:13http://getcsr.com/cgi-bin/PzVEVRgx1/Offlineemotet ext epoch3 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-21 22:34:01b284b37491041636712a4f5656ade57e279af7f50cc4848d93e6a0f908a9aecfexe Heodo
2020-10-21 22:04:312cb85d748c93446a6bb2f5ef170900d923fdb8aabe361b7acd6f046e9dac8c05exe Heodo
2020-10-21 21:45:1449c781c1659e8a5ec2811531438bd4b429a26dbc372640123355e5749d4befc5exe Heodo
2020-10-21 20:47:52145a1639a3226b78a14de68652a3b44f6d788cff8b65daafeb929050933e5708exe Heodo
2020-10-21 20:18:37d9243ec4fd9d6af70dadc7d6e88a005b893c33f8f1915ee07f83d5e7e4fb7861exe Heodo
2020-10-21 19:39:058b91238e9f57cb24be721b7f4e60a3c50e7656c9ff7428da176100bb69cf5fd8exe Heodo
2020-10-21 19:29:15c478af04241e9c7003118b427b6292eef96bf7b3d8103de4201b36f9c0fadbc8exe Heodo
2020-10-21 18:44:2978e1bff35bf33d1840221c811bc0ac78a28389b57a496df1acf36cd2453c707bexe Heodo
2020-10-21 17:58:47fd3b733b21035f175d98ea6f97913d475897a4858d64f21bb90c8d0592713a5dexe Heodo
2020-10-21 17:30:38dd2ea31894de09713e2b2aa36541f76fef3c2ec1ea1921e7a1ef5be94ce2c847exe Heodo
2020-10-21 16:59:018a41bcbb71b216034d58af3db803fe1419c57bb6e6a42bb3855dc515d3560173exe Heodo
2020-10-21 16:24:16e2bfc2de5cc767e01122b16c0c7479a617269805298e8e6f1396cd23790dd31dexe Heodo
2020-10-21 15:55:59d608383606b21060b023a902a2994de1da9b84732d1c988dbee82afe49ee274aexe Heodo
2020-10-21 14:50:337f76474fe28fc22c35c27f688055393c4bf478d59ffbb97a7184d943c84ecafaexe Heodo
2020-10-21 14:31:3993bcb7297020fc59de2e0b54ff17280cc5f7fc922196ba7951d03b00f2566210exe Heodo
2020-10-21 13:33:434447f7dfb7c8ea679abdf915be92e3adf28e5643d613bbcfb4112a0b4675beb4exe Heodo
2020-10-21 13:04:16c2bde00109a38dc5004f3d8e3ed6afc1ca63c85e0ecc80aec7c9a15703528f41exe Heodo
2020-10-21 12:53:108cd1a052116ab33ca55b46583d7b6a2ede79327efa53a7a1e157a7e9b15c69b2exe Heodo
2020-10-21 12:15:203664f99d1833cc649aa985fc44b7b857d4d00bf93f343edcf2044a9daa69fa87exe Heodo
2020-10-21 11:47:53db7085c172859f6363e0c7bf0dca07ca32f29f8a59c80dc14d7bb77e195936c0exe Heodo
2020-10-21 11:24:04ed68489e72d0a3b42e8114f9bb3c767dbf74fd303c46f10b8c4476d3c2d7e74fexe Heodo
2020-10-21 10:44:4279c22c6ce328e98ae61da247c07b23ca694ce85349c8af6dc3af1906559b910bexe Heodo
2020-10-21 10:19:31e49bdc779eeaa52e085b217a5efe13fbdccce4d33c6b640ddfde03d607a30bdeexeHeodo
2020-10-21 09:51:2780bfc8a6cfb037475114e77b5bf8c09b7bfde6598a3b94fd2dc568d90f00c8f1exe Heodo
2020-10-21 09:10:240852b9322930b7390e327020cf56119b910cf8621f03ef99b38ea0e41c9ca4acexe Heodo
2020-10-21 08:57:36f7ec8fbded0cf949eb99634f9b1f0365bd4de3b62aab7411b6ea1ad1e04ad9ebexe Heodo
2020-10-21 08:23:048526b21c68bdf5391b95f4916a6f4002ff59b3977328d072dc1ce588c10cc1e3exe Heodo
2020-10-21 08:04:242dffb2598c40e27fb48ab0f645bd95128257e7a34b0ef0fe602347cec8e94702exe Heodo
2020-10-21 07:51:375d7294d4fd7f8e1fd45b2877e5f1e91cc0dda4e03ca7b83d0fd8c353179ba733exe Heodo
2020-10-21 07:36:52b9267780b57ee6ebb13b7fd8d6ccfe2dcbeaf2109b54bec6c49900753ebb7480exe Heodo
2020-10-21 07:04:347e31fd2a73566c17666adde5796f6693f567b580f9464e2fd4dfa0da5e229fd2exe Heodo
2020-10-21 06:19:01b1dd9459ffeb6eac406fe2d44d644e8e28eca36743dc0f6bfbf4a77092d85a12exe Heodo
2020-10-21 05:59:551b8f330de2f49ea6e983ee8f6d77b12955ab8ec061966f273a6d08911324f215exe Heodo
2020-10-21 05:26:264a698bb7e7205c76f8045b47cc33b5c7570009bf7522440bd0a9960ef45a212dexe Heodo
2020-10-21 04:48:57b1fa38147bfcd1af4a2a523e654be363f5a71eda25c7f9acc491e680dd824bfaexe Heodo
2020-10-21 03:58:1917f74534008735a566bf098d9444e9d8321baed735298afeafed41cc82e6ee5fexe Heodo
2020-10-21 03:31:1040db1a50cea316ed7251b220fb0b52650235777b4f3593cfc62d9caf91ffeb19exe Heodo
2020-10-21 03:13:32e351b32f71f765fc01aca41b1c1e2adb272920efbe4e27cb177cdaab59de2318exe Heodo
2020-10-21 02:50:55f9e0c4a50c83c6742d7a4c44b26566818f72099461476932a0100daf4c83e2faexe Heodo
2020-10-21 02:23:41cd474f336c647e536405f15678b81f1682ade3e4065f6b71d696bf92756f2a43exe Heodo
2020-10-21 02:00:5895617f2d5d1c4d2ae224f552b4a0ebb1b27858e7b44296f60c40a303ac51c5faexe Heodo
2020-10-21 01:49:5637f5c6699f22095b11145060f016be4aa1ed47ee93b14bc69d6b1d68c2271de8exe Heodo
2020-10-21 01:30:181f36cdcfff88020592109d910e39b500f4a460af5f6f880aa98c15636cd2867fexe Heodo
2020-10-21 00:58:135edc66ea925e5590558b30fc94b4b822045c5fa93f3a5d448d1dec9505f6dcdaexe Heodo