URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: icosmo.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-17 12:28:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 12:49:25 162.55.94.140static.140.94.55.162.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes
2020-01-17 12:28:07 185.143.233.5Not listedAS205585 ARVANCLOUD-CDN-IR- IRno
2020-01-17 12:28:07 185.143.234.5Not listedAS205585 ARVANCLOUD-CDN-IR- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-21 04:32:08https://icosmo.ir/wp-includes/gnmem-go2xe-7551/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-01-17 12:28:07https://icosmo.ir/wp-includes/attachments/tbxj4...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-24 12:43:14d4a5dec72600091f43cc79f5efc5b76ed09571f1a906a6fe4400b3ff08341638docHeodo
2020-01-24 11:11:20d830dd74d73625f82a36da760445920cea41b3321cba4769dd421d38e5c8b366doc Heodo
2020-01-24 09:40:2321ed646e9c73d65b5355a50adb7b3a7b2f6d76b45d4248e2ad2480fd784ee8b5doc Heodo
2020-01-24 09:12:15e6227f508ea8149469cf318e6939e1fd1d8b32b728997677e8220d7c4b827ac3doc Heodo
2020-01-24 08:09:26f650d229a5a7baea3cf86104f874121c82bb34994d2be1d3344cf45769387accdoc Heodo
2020-01-24 05:25:397c181b5800d9b531de9f431cbd6947e93f55ac0e5f6fcad200acf2466f411a8cdoc Heodo
2020-01-24 04:13:221824cc4bac3c95af19bb19db000fa09999ed3e4ceff6bb1ca9af0ab4a96104e4doc Heodo
2020-01-24 02:42:31614057ec99d029b526fc3313b3385293cbb2a480d15596dd0a975d679fd753d9doc Heodo
2020-01-24 01:10:305c566546a1462e17becc0023ddfae0f8e4d8b495e4feda5bcc5f7fa52e0ddd0adoc Heodo
2020-01-23 23:53:314d65aa1d4d4356e59a68839a7e437a4e3d207e6bf481c90baf4ba6de5b9d0ed4doc Heodo
2020-01-23 22:21:224cb4d8d3fe9f861f5ab75bb11d23fedf98a1561b3aac9173f5dc211b8bb8bd5cdoc Heodo
2020-01-23 20:59:0169896fb1907aeb3711bc79924a6aa0f9d636605647439f36e14ad1e7c1afa917doc Heodo
2020-01-23 20:40:15af8976ac691aa40327d9844ef283ec4de84fd38c56d57218befd747516e4e92edoc  
2020-01-23 19:27:1612958a0020162751f99e336844423a03e94d65328cc2bb55a570293e54d2a0c3doc  
2020-01-23 18:32:133475216fd7f40791c7a6f620a37544ce6ff9866f4ade999ad3e4eab76ccb91a7doc Heodo
2020-01-23 18:16:4693500a32e011f40c983cee5dd2d53b447421643672ec0823b81e5f7d5125a6eedoc Heodo
2020-01-23 16:59:043ceb6736ad41ce7eab6677db54901559e0f3aec143fea7d74390afa03e0ec421doc Heodo
2020-01-23 15:38:069bbfe0b457184f41255832ce9e3b15e25fe0bdb51a9ecf942163063c7f38acc3doc Heodo
2020-01-23 15:28:16f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67doc Heodo
2020-01-23 13:56:164efe99e760c862d17d3128bc8c9bfe85a4512b981ac9944bd6f3c38d0d02651bdoc Heodo
2020-01-23 12:48:57c72dd27b499d4dea90b30a82818446418aa2fe8c1cfade8a1912d1e757a4204adoc Heodo
2020-01-23 11:28:50aa561ec45a890d783fcb412768c706f829bf7648de033cdd190fab9584ed7a40doc Heodo
2020-01-23 09:57:00bcd78fb2ae376c31ea21a7d1b7d110e4dd0a49c9a8261bc5f68816e4d1091bbbdoc Heodo
2020-01-23 09:39:1493cac8f7e51e270b89a9c834216ec2cdc9273ea5cb5cc6f31bf7d2b145c36776doc Heodo
2020-01-23 08:25:1368ac922c713a804c7deb999f07b98b907019e4c339554a965ee4251d5459b660doc Heodo