URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: jesclongroup.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-14 03:30:04 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-14 03:30:08 204.10.38.148shared20.servers.ndchost.comNot listedAS33322 NDCHOST- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-14 03:30:08http://jesclongroup.com/UCCA/efrzNaxMV/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-14 15:08:523faefaec25266917cdada868fc8076b16e9b42382e82bfb5018562978d0085a1docHeodo
2020-08-14 14:44:50022cf3a8bcb181e5218ff3a6b7e759e94462df01ff93902560371dfa2ffc0950docHeodo
2020-08-14 14:20:49e25abc26006918a7b3aebd6972159b23fd0188c75af859831bf0c870f839a487docHeodo
2020-08-14 12:47:038668a5aae3e7db513fdb925e16313049037536bc67a86ed756b682c98b7f6f09docHeodo
2020-08-14 12:30:364935ab1182453885ea821cc714b1679ae7eeb54bb744fe13f52ad6e954a7f785docHeodo
2020-08-14 12:08:126969c9659df92d53fbfae853c8c208cb0e09fc6acf7dce23773cb66cd060294ddocHeodo
2020-08-14 11:46:597dc64cdcabade0fe1b2cccc83c3a256efb0de22bbc1e8b17a072104e393b3b26docHeodo
2020-08-14 11:30:3178933fecf248691aab0f40469c0dcd29e03ea9922aaf89b7cdc830b802cfa8a9docHeodo
2020-08-14 11:09:53187f385bef1fda1bcb05ef62b9e4189a16432875e3fba2d0b7cf1fd6e6739de4docHeodo
2020-08-14 09:39:06b580ef15f157d6c19b61810ddb5f085007685d55693d05cb54782cb52bac7e2bdocHeodo
2020-08-14 09:13:13b491fec759260d8a1c9a3ae8ca946359d8abd506b683a71ee5a45fb91e170236docHeodo
2020-08-14 08:48:524af3cc1ac4ee4610fa7671fdc8b02ad17ad4e71433250d2ab04291fc1f5e657cdocHeodo
2020-08-14 08:32:06101c35e8c776b8ae43e1a8703b8793462210ca7ed543c075d7fbe88796826773docHeodo
2020-08-14 08:10:22f841c145c39f74c12260a67c686e4dde761614e633f204a3e68f47750f2e6d1fdocHeodo
2020-08-14 07:49:05b873855abe6ecb687a4df753ed5f4882475ca551c53ffc20ef18b3c896115a91docHeodo
2020-08-14 07:29:0927db24afe51c643a809e559c190b96146022ef6d3394b8e990c6eee4bb9846acdocHeodo
2020-08-14 07:08:06fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4ddoc Heodo
2020-08-14 05:37:093132acbb0aa02f175f2e8bf589a53e732564cf73f1f003cb64c842ba52d3c889doc Heodo
2020-08-14 05:20:17845f584a4b58e05f5eabb64041142baac8b97a971f88d4cb2544c4ac3af97a3adocHeodo
2020-08-14 05:04:04dbc3f242e959a4c3398cc0676dacb940b4253a18f4a2be2d3a1aebb7c1f62d74docHeodo
2020-08-14 04:35:16d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6docHeodo
2020-08-14 04:13:24a5cebe26ebd797b743940f94cd3b74255ae3864a8042734c1b430e3da0198e2bdocHeodo
2020-08-14 03:30:0779ea3e6251e22a744018845dfa9472128b35301f22c571781bf17b288237e411docHeodo