URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gobisz.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-07-20 15:42:03 UTC
Total malware sites :1
A record(s) observed :30

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-07-20 15:42:06 156.67.222.133Not listedAS47583 AS-HOSTINGER- SGno
2025-06-16 14:47:44 92.113.16.82Not listedAS47583 AS-HOSTINGER- DEno
2025-06-27 23:58:58 92.113.23.99Not listedAS47583 AS-HOSTINGER- DEno
2025-06-30 15:49:09 92.113.23.97Not listedAS47583 AS-HOSTINGER- DEno
2025-07-02 03:46:56 92.113.23.96Not listedAS47583 AS-HOSTINGER- DEno
2025-04-27 20:48:50 92.113.23.81Not listedAS47583 AS-HOSTINGER- DEno
2025-06-29 07:00:27 92.113.23.77Not listedAS47583 AS-HOSTINGER- DEno
2025-04-27 08:34:44 92.113.23.74Not listedAS47583 AS-HOSTINGER- DEno
2025-07-06 20:11:00 92.113.23.69Not listedAS47583 AS-HOSTINGER- DEno
2025-06-23 01:12:33 92.113.23.251Not listedAS47583 AS-HOSTINGER- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-20 15:42:06http://gobisz.com/wp-content/wbhJWVHG/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-20 22:35:586b73218a2ca9d7848e2b60f627be21b829027bdfb8250070d7642b5b24977621exeHeodo
2020-07-20 22:18:3321d3b8153a1a0a09bead5cccb498673549b9acde40df8d2ab068406f4bf57910exe Heodo
2020-07-20 21:54:45e63c5ef9840276af8e0d92d5919d8eb8cf891791b045434110788611d1f22eb9exe Heodo
2020-07-20 21:30:31bb4713ef29623a6256f33ab9d28b7447f7619ab582137203e577eacfd2ac7c45exe Heodo
2020-07-20 21:12:1672bdc44ecc8da52ab5070cbe2c7b8c7471fa1b7e95d136fa1c4597c2be67f715exe Heodo
2020-07-20 20:41:4942f519af97587fe4375b948f6a24f10404ccb3d734369d4f67bbec1909cbdaa8exe Heodo
2020-07-20 20:29:157d5ff1a11f2893105d2d39e73d16fbb211f52952ab4812522689697c53627399exe Heodo
2020-07-20 19:46:404349475b063f5cc95f741d4fc043b10f772cf255d3b5b7dc2a7d8ae779b5345fexe Heodo
2020-07-20 19:35:21f2f2bb69fdc82ebbdc6c9d604d365e065100e7e786b1ac35bca0864c450f6bd0exe Heodo
2020-07-20 19:24:05751b94bf7cb28183625fe193f5596a3b697c7c773812314c884fddacbf0b5814exe Heodo
2020-07-20 18:57:16ada41e1144e56f00e3e6d376c5e97d8ba3990e041fcbebdef57ad67047f908cfexe Heodo
2020-07-20 18:27:50e7722856c925deab6829895821243e160f00cd8c3d02b74df5544078d9635356exe Heodo
2020-07-20 18:15:3067c1c4675cd64d40c2599d62f900700542f7e9e52c1cad16355a142b0bd16e20exe Heodo
2020-07-20 17:57:1340464843be65df09136a73e92df94134f7e398a261db95204088400db99dc34cexe Heodo
2020-07-20 16:19:41f59773cf6a605a1f648582e4b297570cf66bce79eb57b45dff75e9da3684fd9fexe Heodo
2020-07-20 16:11:2327f90bdf6695b41e81bca1234cd0012ddb059e0846617ec037203a26ab68c11bexe Heodo
2020-07-20 15:52:359114c46c6ca56a935c10f8b564f6a1acc3247baadb3f433d10c3ee98893250c7exe Heodo
2020-07-20 15:42:051e9b151d5f3fe179cd2728e18e1d7b69245951fb786e8d48d543de131f56d5b7exe Heodo