URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: hi-so.net
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-29 14:00:34 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-04 12:56:48 103.141.96.142sv10781.xserver.jpNot listedAS131965 MAINT-JPNIC- JPyes
2020-09-29 14:00:37 202.254.236.159sv5158.xserver.jpNot listedAS131965 MAINT-JPNIC- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-29 14:00:37http://hi-so.net/4L3F3pQSWq/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-29 23:13:111c66d607d768fda8908683a9139ba103d12f44f588c622dace25ea46c28f9945doc Heodo
2020-09-29 22:54:1308c3a51969b9ccfcd46ad14ef1a7599a798c21e693a582ac6d8f449f77f4fc09docHeodo
2020-09-29 22:28:068666706e9ee66b8e782269a6c387b2ce242c017e7507bc5d65fcbedbc021f2c4docHeodo
2020-09-29 22:11:107b65d8ab639b2e52bf89d1991cd330f6290b79269e2699b295b134f62689d29edocHeodo
2020-09-29 21:43:09bd56a042ecf4e68f3f6d427ca4ee9ad03267b1e53db58ae19e8335e34f6231f1docHeodo
2020-09-29 21:37:18cdbc3d9af98086634425aa8705246094a3b602fd00a7f35717208a55a4da2144docHeodo
2020-09-29 21:01:203ed38db3201fe400b1e0533ba551a1f631a550297afec1d65ce776dc9ed958e0docHeodo
2020-09-29 20:38:172225d21fb51eb2731d606c94088c9ac64900275d5970515cba58374eab5dcdcedocHeodo
2020-09-29 20:20:4966e0d59d4c4e46b4e5589d41dbb45277b6dd25aba1efb68deada81d72a492aebdocHeodo
2020-09-29 19:54:4143302ab823d78926b1d6c64d95d04cbb45c97d5d8128ffe8eacb17bf0ed2ed24docHeodo
2020-09-29 19:44:57d43559c27961577b292cd3c8f65aba9e464eea39d831d95cd2155c885c74d96fdoc Heodo
2020-09-29 19:24:4271052fa8607af31f75e8e9fa311bfce8992c7a67551f8f15b281547f57aaa0ffdocHeodo
2020-09-29 18:55:286a026a05a3a131e3e0c18682b71562c9e66f18aa9fa41342f8e4f1638346368bdocHeodo
2020-09-29 18:37:58275a46a9c86fcb536d7dee38a273fadc27066204b68ef852423568f9f925ae81doc Heodo
2020-09-29 18:03:403939481b8307ac66766600073b45ebd146e9675fdb765f31f650dca3290f91fadocHeodo
2020-09-29 17:35:5194664f71a4235a5be2e24ea979edb2133d68b3d4ddd2a3cad56741bedb13edc1docHeodo
2020-09-29 17:22:119d62529a510f5ff1233ee41b2df2feb66813e33d5827aadd11b8d28984fd4bc1docHeodo
2020-09-29 17:03:22dfb7fbf86fb1570a1800e0e7134f58fb4babb231287e95aa698ff283ce1b45e3docHeodo
2020-09-29 16:35:05ebe5c60d0f35c3d6f839899e01aef73d251b2ba41e0d7ca848d1302b1c9906ecdocHeodo
2020-09-29 16:20:420d6a4adbdcf1eb88796382eb5c208b6bb92242af7b560d07e66647478e265758docHeodo
2020-09-29 16:01:3765021d78e36b926f2d707ed3ec8162458f8f9fa93b435a74d8ba57b7a46b5fe0docHeodo
2020-09-29 15:48:15a2983168d457ca0f8dcaa3646efbe123873003af21cc494c8171175df0e0a9ccdocHeodo
2020-09-29 15:10:33485c489c206a25350005243077ba88ed94b9261239ea06d06e1d5a883d69a70edocHeodo
2020-09-29 14:56:04ae306a6cc155bf68ece16f8f6a7b65692511d84af5c2d0f8375c31975b1b2769docHeodo
2020-09-29 14:15:0876b5f9e5cb59fcac0d2e8109a019fc56b03e5a26b1a0406ffc15f63dbd6514ebdocHeodo
2020-09-29 14:00:37c45e98d9c02f898d3f7f7f86e60bb708155c604c1125c3dac174e757bcfeb775docHeodo