URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gsx.life
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-23 10:48:05 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-08-28 17:47:28 42.193.44.152Not listedAS45090 TENCENT-NET-AP- CNyes
2021-01-20 09:04:37 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2020-01-23 10:48:14 49.235.42.242Not listedAS45090 TENCENT-NET-AP- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-23 10:48:14http://gsx.life/wp-includes/9jsd-lb2-09/Offlinedoc emotet ext epoch3 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-17 13:40:3261174da5eeb4a6cf230ca57c3c77a258fe8259edcedb6566fadb3a8de4f47eb2doc Heodo
2020-06-17 14:54:180db7f4e0e5583cb3a13ce0452d4461f9d993207fdf0e03d0b828cc15c8d7dd4cdoc  
2020-06-17 14:29:47cbea13d411b05950b4b21a2c2135506dae3c82ff30af3965d4cc32371079d102doc  
2020-03-19 17:16:00f46b9272a5cbff9ab0cc989bce4f6113a9e270c6b6bf9efd201f26ad657f9388doc  
2020-01-26 22:51:00983ddd1518361a6f16f1b4f4980f9f8e195ab46794ddb14935f83c5a93781f17docHeodo
2020-01-23 22:19:484d510b0eee8d7f749ded15111532566dea606d52e90b905dbb5d67d8282e2231doc Heodo
2020-01-23 20:57:32d36e75fa61fbc43888ece86dae242e0123a0047b493fcf7e19a77659e8e7c952doc Heodo
2020-01-23 20:44:4515b199f8ba35174c6082d599128c694edaf953347bc41c55212437e09f16f741doc Heodo
2020-01-23 19:25:32f1d7ec05895eaeda241064ec4901d67a5372659817cab6154477a414177feca1doc  
2020-01-23 18:37:08d0ac8ecbb19ac38fad42155fd608a1d725a6b9e1a38e653be9b73711c920d788doc  
2020-01-23 18:14:3362b81000c333c1537dc9c8324e3f259b77c07479f39f0542e88c4349797fbf57doc Heodo
2020-01-23 16:57:199a2c55b454275e9bc8438979a830af3f17f4fbf87c418b5e4405d154686e2beedoc Heodo
2020-01-23 15:42:4389d74bab511baa47fe6842a7ba93a2f93e543cb1246f0339d55added41938077doc Heodo
2020-01-23 15:26:24f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67doc Heodo
2020-01-23 13:54:194b1fc8d62a7e490364bf85388322e779c0ff8a7adb39bfff5b386d7ba08eda1ddoc Heodo
2020-01-23 12:47:17d91ee6af9a42e6c4c90bcc0602f6ca687bf444b88a183867d943b365bf8a7db2doc Heodo
2020-01-23 11:28:543c8f1b91ec9081fe9a7f3a148e86f65019a450a87c13110116b93cfab2bd72efdoc Heodo
2020-01-23 10:48:139f60f90c850b731fbe9b9939142a6fa7f4d34243ae46124bfaceb8bd29ca97f1doc Heodo