URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gkdon.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-16 21:44:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-20 19:59:04 81.177.174.12Not listedAS8342 RTCOMM-AS- RUyes
2020-10-16 21:44:04 81.177.49.68Not listedAS8342 RTCOMM-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-16 21:44:04http://gkdon.ru/wp-admin/1S6VmpyWk4BHE/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-17 05:31:36294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092docHeodo
2020-10-17 05:08:06ea4cb3d56a4e049d8d0e7d1e30ff96c6b4fd216860a4c48ed248940702f3b7acdocHeodo
2020-10-17 04:03:16c147f6f4d8e08ce92756aea055fb18dc3398e77ce2ba5a71bfa3d6eb5f3de750docHeodo
2020-10-17 03:38:491cee91ca2689e165e0a72614f98d0dc71da6671ecd0e7f32bb3d6d2710e8dd0ddocHeodo
2020-10-17 03:11:47ccad29eac2b2a4c03fc1c9a9ac36544345fb0a5f454746c05dbb5f02d4d53210docHeodo
2020-10-17 02:44:05971e189c279099a876618c3226ef35e5afc62b91daf3b8bde466a424fdfaa063docHeodo
2020-10-17 02:27:513fef345a1fa8f779f98589ca704dff21e59f8842175c3cdab8caeb16e5e61ad2docHeodo
2020-10-17 02:02:406820620122b2210629007eaae85c11949f1d113edfa9e10c0a0678069bcefa83docHeodo
2020-10-17 01:33:20674b59aa10f963845214c91833225375d26e69ccece07609e8a5425a8d952346docHeodo
2020-10-17 00:59:065422842242a23ce0b01dd8151fb9d86c9c6b41ed43c792e7c4b714cc2cd2a1c4docHeodo
2020-10-17 00:46:55c64264c7336d7e9f516999fa287be55be63b634b63f5ebbf1bab24e38ada5e8edocHeodo
2020-10-17 00:22:391e52bc38ce5e8a3c4da25a7c7e4d8169a31fa22bfdd9e43759ff57d25b40db02docHeodo
2020-10-17 00:22:381e52bc38ce5e8a3c4da25a7c7e4d8169a31fa22bfdd9e43759ff57d25b40db02docHeodo
2020-10-16 23:57:19a9d9b8357ff803bd36d7bd0c12c770487fe774ccd22e81318606bad0f6ddaf90docHeodo
2020-10-16 23:27:26528b63ef8c44d0a5b08974fb6ad9efa60e0021ce6993d25b30ef1b90c00df222docHeodo
2020-10-16 23:01:355ee53916c491a77206e7a09eb75c02983fae90474ddcb7d0099a47113b4675acdocHeodo
2020-10-16 22:33:43c5480c5bcd7c9b06e744ebfca49ef98e45da1200c5e3762d6b47d9825189f3eadocHeodo
2020-10-16 22:15:425c58c91ffdffd84690c6746f6afc2eaeacd03df2e4a83c6e662755624113cf5bdocHeodo
2020-10-16 21:44:044773da38da0ba3154bbb3b813c803bd6e1f9ab3bad1888f1402f7b17073620ecdocHeodo