URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gubarevweb.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-31 00:13:03 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-31 02:50:36 45.130.41.86ssl.planet.beget.comNot listedAS198610 BEGET-AS- RUyes
2025-04-28 15:14:41 45.130.41.4ssl.mario.beget.comNot listedAS198610 BEGET-AS- RUno
2020-01-31 00:13:04 87.236.16.90ssl.plasma.beget.comNot listedAS198610 BEGET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-31 00:13:04https://gubarevweb.ru/wp-content/browse/b86jb85...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-02-01 11:18:438ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0docx 
2020-02-01 03:20:58bc70c47eb8ddf7aabf6872f9bb19555fc0ad12991757bf2caeb37b7acaab1177docx  
2020-01-31 21:06:2827c873f92aeb9d4854782e11447aa7e077d09134662f62e4fc7e54e50b544926docx Heodo
2020-01-31 14:03:08dca79d7d9bcff3aed5711c06717a22e7d2dc3b99e30467ad96fc36f80c80744cdocx Heodo
2020-01-31 13:03:3132611bf81a7c08569474e590f6401621b66584f95d22d97226fd7e43a4b84365docx Heodo
2020-01-31 00:13:04b492dcad2b7ad9c1080068a017117e9adf7f158c0d39f9598b69cdcde3e447f3doc Heodo