URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gmsmed.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2018-12-03 20:20:02 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 08:37:48 91.121.234.115Not listedAS16276 OVH- FRyes
2019-05-07 05:06:16 216.55.169.164mail.smartechbay.comNot listedAS18501 JOESD-18501- USno
2020-01-12 08:29:17 209.99.64.51209-99-64-51.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno
2018-12-03 20:20:05 162.241.219.23box5608.bluehost.comNot listedAS31898 ORACLE-BMC-31898- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-11 17:37:03http://gmsmed.com/wp-admin/EHdWd-EiEQqdVguYHl1T...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2018-12-04 06:49:03http://gmsmed.com/p/Offlineemotet ext exe heodo ext abuse_ch
2018-12-03 20:20:05http://gmsmed.com/pOfflineemotet ext epoch2 exe heodo ext unixronin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-11 22:26:09b6cfe1983ff1d2fb772c8e68fcbd69f805d5b488ded023a6c13de39965af95f6js Heodo
2019-04-11 22:04:167ca4540e7f5caf44b46378c7861c9403373c7b752034f5ef7d4bc06d2c1e28fadoc Heodo
2019-04-11 21:45:18e2a11a63b4671b0f5f73973dd064e0bac6e5b79ccafef064488da5a3b885146ddoc Heodo
2019-04-11 21:33:1356551134c8787e629bae380e03f286b5060d0034375a843cb736ab53a4de8b05doc Heodo
2019-04-11 21:01:144cbf340b5b3e21206fcdca35016b0d5045f2c509f982961585407c451ae2a238doc Heodo
2019-04-11 20:30:163501e4e4c86e7f0acf77d18b68f9adce40422224d04d148e27ed02578df76c92doc Heodo
2019-04-11 19:58:162c455198539fef7e43c06f1715f7d947896c98f3b3129c792cf086959edbd295doc Heodo
2019-04-11 19:27:17b1a6afc983ad35e8c5cae8e6ef315e43f6555983a863c141872698c9135959a6doc Heodo
2019-04-11 19:12:12d194ff91d5c737ca5fb69b24e3118a426e54b65e968824691eb9bd463f6cc4d1doc Heodo
2019-04-11 19:04:20713f84fc17d6c37720e731f364ff47c9dee7f3142872a24d35f81b86973b3b1fdoc Heodo
2019-04-11 18:48:074a6ddeb9d4f38ed9a77ae3fef4d181697104ee065e3a1d28a620bb3f995f7469doc Heodo
2019-04-11 18:42:13ad23b779d4003171a8b5780144004d88e5b01c16e74b2d6ec91c2805f57e6da7docHeodo
2019-04-11 18:22:187184986780a4c1f14b49e53f064518f0c5c12b47d12a5ad687a0df344b6188f4doc Heodo
2019-04-11 17:50:178a1a1d1ca48c3886c2dd482907ce8981495899d7e19bb0c2e0b873bcc7e62ec5doc Heodo
2019-04-11 17:37:037b250036a5d97bd4ea1deb958618023426b5b9a10a98da4f02beae13c60a02b5docHeodo