URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: iran-bitumen.com
Domain registrar:OnlineNIC -
Domain registration date:2005-07-31 12:50:57 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Blocked
Firstseen:2025-03-18 12:11:05 UTC
Total malware sites :24
Online malware sites :0 (0%)
Offline Malware sites :24 (100%)
A record(s) observed :31

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-05 09:12:20 154.89.121.48Not listedAS142286 HKIDC-AS-AP- HKyes
2025-10-16 18:44:13 172.65.185.109Not listedAS13335 CLOUDFLARENETn/ano
2025-08-05 09:42:07 134.119.176.28Not listedAS29066 VELIANET-AS- FRno
2025-08-05 05:28:46 134.119.176.24Not listedAS29066 VELIANET-AS- FRno
2025-09-03 04:33:53 192.155.108.149Not listedAS29066 VELIANET-AS- USno
2025-08-04 19:17:48 134.119.176.27Not listedAS29066 VELIANET-AS- FRno
2025-08-05 11:46:47 134.119.176.29Not listedAS29066 VELIANET-AS- FRno
2025-08-05 03:22:55 134.119.176.25Not listedAS29066 VELIANET-AS- FRno
2025-08-06 06:43:17 134.119.176.26Not listedAS29066 VELIANET-AS- FRno
2025-08-06 12:18:47 134.119.176.30Not listedAS29066 VELIANET-AS- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-18 12:50:08https://iran-bitumen.com/wp-imported/rau.exeOffline JAMESWT_MHT
2025-03-18 12:49:32https://iran-bitumen.com/wp-imported/Crypt%20B.dllOfflineDanaBot ext JAMESWT_MHT
2025-03-18 12:49:31https://iran-bitumen.com/wp-imported/NoCrypt.dllOfflineDanaBot ext JAMESWT_MHT
2025-03-18 12:49:30https://iran-bitumen.com/wp-imported/Crypt%20C.dllOfflineDanaBot ext JAMESWT_MHT
2025-03-18 12:49:15https://iran-bitumen.com/wp-imported/FIRST.exeOffline JAMESWT_MHT
2025-03-18 12:49:14https://iran-bitumen.com/wp-imported/Crypt%20A%...OfflineDanaBot ext JAMESWT_MHT
2025-03-18 12:49:14https://iran-bitumen.com/wp-imported/CRYPTASET2...Offline JAMESWT_MHT
2025-03-18 12:49:14https://iran-bitumen.com/wp-imported/x32_log_se...Offline JAMESWT_MHT
2025-03-18 12:49:14https://iran-bitumen.com/wp-imported/chdisbnted...Offline JAMESWT_MHT
2025-03-18 12:49:13https://iran-bitumen.com/wp-imported/x32_log.exeOffline JAMESWT_MHT
2025-03-18 12:49:13https://iran-bitumen.com/wp-imported/chdisbnted...Offline JAMESWT_MHT
2025-03-18 12:49:05https://iran-bitumen.com/wp-imported/CPANEL.txtOffline JAMESWT_MHT
2025-03-18 12:49:05https://iran-bitumen.com/wp-imported/Crypt%20A%...OfflineDanaBot ext JAMESWT_MHT
2025-03-18 12:49:04https://iran-bitumen.com/wp-imported/delelel.txtOffline JAMESWT_MHT
2025-03-18 12:49:04https://iran-bitumen.com/wp-imported/faylA32.txtOffline JAMESWT_MHT
2025-03-18 12:49:04https://iran-bitumen.com/wp-imported/faylB.txtOffline JAMESWT_MHT
2025-03-18 12:49:04https://iran-bitumen.com/wp-imported/fyleAnon.txtOffline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/last.txtOffline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/txt/CPANEL...Offline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/faylC.txtOffline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/deelel.txtOffline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/x32_log.dllOffline JAMESWT_MHT
2025-03-18 12:49:03https://iran-bitumen.com/wp-imported/faylA64.txtOffline JAMESWT_MHT
2025-03-18 12:11:06https://iran-bitumen.com/wp-imported/typed.txtOfflinebooking ClickFix FakeCaptcha JAMESWT_MHT