URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: huffingtontribune.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-02-01 16:02:30 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:31:01 192.185.244.84192-185-244-84.unifiedlayer.comNot listedAS46606 UNIFIEDLAYER-AS-1- USyes
2021-02-18 05:17:13 50.87.144.143gator3108.hostgator.comNot listedAS46606 UNIFIEDLAYER-AS-1- USno
2021-02-01 16:02:33 198.57.247.111198-57-247-111.unifiedlayer.comNot listedAS46606 UNIFIEDLAYER-AS-1- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-02-01 16:02:33https://huffingtontribune.com/talt7wf.zipOfflineDridex ext stoerchl

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-02-02 04:35:33340f8111729221f47c382b71f107f8b7a8e8d111a42bd11af3dfbfe2232f3778dll Dridex
2021-02-01 21:25:36ee3d186893d084860c90718bc56845321d34866f933fb7eb1d483d4df3814ec4dll Dridex
2021-02-01 17:50:552954fff16d963d718ba0518ebdcadb61c71bf4d5cdd13d4c6bc7058329229c21dllDridex
2021-02-01 16:02:32b86c5596a0e616d559c17a0df56a9faf93a36b87db4dc919181d3c8acdbaf137dllDridex