URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gfnl.org
Domain registrar:OnlineNIC -
Domain registration date:2010-09-22 10:42:34 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-02 15:34:04 UTC
Total malware sites :1
A record(s) observed :19

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 01:24:59 109.74.196.164euuk1.armadaservers.comNot listedAS63949 AKAMAI-LINODE-AP- GByes
2025-10-09 17:54:39 192.155.108.148Not listedAS29066 VELIANET-AS- USno
2025-10-11 06:56:52 134.119.176.29Not listedAS29066 VELIANET-AS- FRno
2025-10-19 15:47:18 134.119.176.23Not listedAS29066 VELIANET-AS- FRno
2025-09-26 16:35:04 134.119.176.21Not listedAS29066 VELIANET-AS- FRno
2025-10-05 19:59:36 192.155.108.149Not listedAS29066 VELIANET-AS- USno
2025-09-29 09:34:20 134.119.176.28Not listedAS29066 VELIANET-AS- FRno
2025-09-30 17:22:33 134.119.176.27Not listedAS29066 VELIANET-AS- FRno
2022-02-10 07:01:34 139.162.207.60139-162-207-60.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- GBno
2022-02-02 15:34:06 63.143.33.122host106.idc-internet.comNot listedAS46475 LIMESTONENETWORKS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-02 15:34:06https://gfnl.org/wp-content/rwdBTLqAfNSYW3L/Offlinedll emotet ext epoch4 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-03 10:49:45557314c94ee8533af1b6228c8813a1990faf8db4d753ccc55eeeeb3a979fadb5dll Heodo
2022-02-03 10:37:372d17e53eed5c35944ada497e35415e860dd00a8d948e0bae8ececd94da90f77bdll Heodo
2022-02-03 10:25:01ff6580cf4b0e251fd19f8c378f08af73bcccc54d00bc8f2cd6220e0b87b3cd1ddll Heodo
2022-02-03 08:43:075941b56da5c2dcabf3c0587772c8cde7a6123d45a91cf65c044cf48940d26378dll Heodo
2022-02-03 08:24:489f7b7a7ef1061e33f1869cdb4add77cfa3f18b5f8a80ca620e995ce23586c8a8dll Heodo
2022-02-03 07:27:375264a127d2bf65e2fb64fbe6e8ceda5aff7c8a450963c2cfd04d8d5b57ad7f95dll Heodo
2022-02-03 06:34:35d17881eeff148619cd9e497433b407475a186e40f4e1b80e02b3fdc2b104345cdll Heodo
2022-02-03 06:19:082fb013bc77a9d24fa9a794bba6fff5ef7641567ea76bf625219a25015696567bdll Heodo
2022-02-03 04:45:52fcb50bec8c90981ce119f2c3f7e41d6969d66155fe851eec1274b9269c4a9fb9dll Heodo
2022-02-03 03:52:5098ada8e5ba451662a4ddc8be92baf6cfb64a090dab9fb62e3729e6ca3736690adll Heodo
2022-02-03 03:44:396e63ed8a2f4e9bd466d49fd4e4251b55d04133020e37ceb6ef59da667fa12f94dll Heodo
2022-02-03 02:37:464922dc98c84d8133f6a90bf9a11c3c8d4665ef33f7c82a59854ec78792693849dll Heodo
2022-02-03 01:52:31f47448ebced206d70d06411a3bce3700c5aff6b7d4ab8590847cf3d104b3da8bdll Heodo
2022-02-03 00:51:59c8988a15b77ae5d8149a630bdf30071b6be4ab2ec3b04239af871609de1dd839dll Heodo
2022-02-03 00:41:4287517ae2bb8961e7ba9203dac1c2317253fbe1dfefe7fd64b8eed608d4bb0415dll Heodo
2022-02-02 23:41:5887568b2047e7f9cb901100c949cf25cc48851b9e8ffb7d10322a406a7ac58199dll Heodo
2022-02-02 22:49:11cf9d942c203f7f3309cd40defb3d683ffdf34458e649292c1cb11c677ac15424dll Heodo
2022-02-02 22:06:022b70b02199daca94f37b4a7c4cc17c538ff764f739b516ba0f08ef16b5fd7919dll Heodo
2022-02-02 21:05:472bbde3ccc2f1dd75bd5f77ad98a5a8449f24cb39f75fd30aca2a378c1ab01ce3dll Heodo
2022-02-02 20:01:2865a4ee893baad75ec245b9c35ee5dd99c19bf0c9cfd63d821353889cfc658f4cdll Heodo
2022-02-02 19:18:120804ea724e7956dec35863b0864a8e582c3c0bfdee015d7b0d30f5fede6549dfdll Heodo
2022-02-02 18:10:51a002f06c2969a8240360af7b5336572c619b4442fec3cde710bfe16f6a87186fdll Heodo
2022-02-02 17:25:50c4691cec3142a97ba0c6ae00d8646c9d977ed4fd57324af326f9a15d8cb2e7a9dll Heodo
2022-02-02 16:21:12f955b3081306fdf1a155c845559d5061fc5403a03444e59ed527736c670a5445dllHeodo
2022-02-02 15:34:0622982e6b2f7be1ecab006062baccfb516c0caf1132421458423767c809a77b9adll Heodo