URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gpsassist.us
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-28 12:11:05 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-23 16:58:46 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2020-09-28 12:11:07 23.229.216.11.216.229.23.host.secureserver.netNot listedAS26496 AS-26496-GO-DADDY-COM-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-28 12:11:07https://gpsassist.us/css/Scan/suNshbSSyzaZ/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-28 19:37:123292fe38076db366610a063cbf27666b3e9e5b7b1e0d5e82dfac2a988d125b22docHeodo
2020-09-28 19:24:2484025f7343277daa58bc982cb0cbf1b86426c8ce05c63d0d0ffaed66a4b7f066docHeodo
2020-09-28 19:04:02c6701fcf28722d5250aa3733bc8253d9035dc892aaea717238ecaecab9e674fbdocHeodo
2020-09-28 18:38:3071a38628c591821a166a062d506bc6b46796bf94f17b1bcc092bb41dec8c3ba1docHeodo
2020-09-28 18:28:05748837bdf7893d4f7240ca6396f25eb971a9829651cb24d330996ed4c2c051dedocHeodo
2020-09-28 18:00:540a5eec11213eda477a74b38048fa996b1b0a33a0a7aaf0aa19909777d89136cbdocHeodo
2020-09-28 17:47:45f5c4e7494229b6e64743d652267a73b78643768765cdfee8782e5b156fd3a5a5docHeodo
2020-09-28 17:28:13daa3c317fc32505e60e473931131c93bda40d01380cc57281d2e7ab9dcc6612edocHeodo
2020-09-28 17:01:1231bd41fe0428d0c15f806a58e21c9f68ae8dc02b2823944caabe3a0cf3a0accadocHeodo
2020-09-28 16:37:55eeb4c9b11f481b21bbada3cabf7d3198edf259ccbec12c21c631a7770369809bdocHeodo
2020-09-28 16:24:11593ae7407c695146a90b5935fb4daaa47bf1b4e14181e09ec639f109ecb6cd99docHeodo
2020-09-28 16:15:29736a92a1885634dfce901843ad45e4a1ea0016b71e18d254b1f02f577afd8adcdocHeodo
2020-09-28 15:57:0485e6292f385e42e2a5da15706af20124c7a219b00d1a449c0d785d718a5a0237docHeodo
2020-09-28 15:46:31c7678263136c72eae4c2d6509a5b7b56e6a1737087b40b9757c0bc424b627fd5docHeodo
2020-09-28 15:23:3239d4d98a6b6ca9daaa9c26208cc365ae6213b572de1c061a178a6a78909f6cd5docHeodo
2020-09-28 14:57:4108a4f15bc80d74cee9e99f6f8abffab083d993aeb388fdcc87491915139de532docHeodo
2020-09-28 14:52:36195918c64e63b45531349c13f9f0ac6099a53d6d05974498542a7f38acc6d247docHeodo
2020-09-28 14:29:49a748f6864ba85fd8d3950f3de775ba684827fad6856a82726df78a17a884888adocHeodo
2020-09-28 14:08:58101fd6ac0d16e8311173436f83f9486238d80008cb3d59a1b292a882f1254230docHeodo
2020-09-28 13:57:53c41f70d35decb29c3b6e8f406423d0747fb4bdbdd66c54a01cf86567c4ce603adocHeodo
2020-09-28 13:31:093a9ad1adfb25f584b952d1ad565b13d074f0a2b396249138449c29016187e362docHeodo
2020-09-28 13:08:188450aba2a0ec49f85af90d65669cd101da214e56fd6081d4e67af00bd05184dcdocHeodo
2020-09-28 12:51:096bf0c29b676a14ea5bce84f7837e298ea09f7d14c0856ff46639e8e418131888docHeodo
2020-09-28 12:27:470d625f86dc6d7a57f7baf86b84854d00b75520450903af8675546dce9d1d2b66docHeodo
2020-09-28 12:11:072070256c212687473c7fb1b4eddf083250f7c00cfc588d07932bebb52dc362e8docHeodo