URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: jitkla.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2018-05-17 15:23:41 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)
A record(s) observed :50

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-02-13 07:00:28 192.155.108.156Not listedAS29066 VELIANET-AS- USno
2020-02-06 00:00:25 104.237.196.116dmpro-serverdeals-us-01Not listedAS20278 NEXEON- USno
2020-02-06 00:10:39 37.48.65.151Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2020-02-15 02:00:23 192.155.108.157Not listedAS29066 VELIANET-AS- USno
2020-02-09 19:00:26 151.106.5.163Not listedAS29066 VELIANET-AS- FRno
2020-02-14 10:00:27 104.237.196.117117-196-237-104.reverse-dnsNot listedAS20278 NEXEON- USno
2020-02-05 21:10:37 192.155.108.152Not listedAS29066 VELIANET-AS- USno
2020-02-27 22:00:21 85.159.233.35Not listedAS43350 NFORCE- NLno
2020-02-05 04:00:25 85.159.233.40.Not listedAS43350 NFORCE- NLno
2020-02-13 04:00:25 207.244.67.215Not listedAS30633 LEASEWEB-USA-WDC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-21 19:26:04http://jitkla.com/images/DOC/New-Invoice-YH3598...Offlinedoc emotet ext heodo ext zbetcheckin
2019-04-19 08:44:02http://jitkla.com/images/Client/Invoice-489698Offlinedoc zbetcheckin
2018-06-30 06:07:15http://jitkla.com/images/Facturas-disponiblesOfflineemotet ext heodo ext p5yb34m
2018-06-28 03:41:25http://jitkla.com/images/Facturas-disponibles/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2018-06-26 13:16:42http://jitkla.com/images/ACCOUNT/Client/Auditor...Offlineemotet ext heodo ext Malware_News
2018-06-25 16:12:05http://jitkla.com/images/ACCOUNT/Client/Auditor...Offlinedoc emotet ext heodo ext Anonymous
2018-06-20 05:45:59http://jitkla.com/images/ACCOUNT/INV44779073Offlinedoc emotet ext heodo ext DecayPotato
2018-06-19 05:25:23http://jitkla.com/images/ACCOUNT/INV44779073/Offlineemotet ext heodo ext p5yb34m
2018-06-14 06:02:33http://jitkla.com/images/Client/Emailing-U48140...Offlinedoc emotet ext heodo ext DecayPotato
2018-06-11 14:23:17http://jitkla.com/images/IRS-Tax-Transcipts-04/2/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2018-06-08 15:47:17http://jitkla.com/images/Client/Emailing-U48140...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2018-06-05 17:04:18http://jitkla.com/images/Client/Invoice-489698/Offlinedoc emotet ext heodo ext Cryptolaemus1
2018-05-30 16:28:15http://jitkla.com/images/ups.com/WebTracking/ID...Offlinedoc emotet ext heodo ext Cryptolaemus1
2018-05-17 15:23:50http://jitkla.com/mambots/Overdue-payment/Offlineemotet ext heodo ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-12-27 16:07:23e2ede8ba59f6c0632644aa43658d0d4d2f7e2f78e2c9e69f0b3a6b3456de975edoc  
2019-11-19 07:42:4756875fe302e20500785ebab45b0b76e6e191abe57cf98455a6372e04a781bf90doc  
2019-06-28 02:00:04b01fceb8531aa85f948d906ae30d561229fba74a314bbb9049541a4a2ee18fe1doc  
2019-06-28 02:00:0428384e04570c07334927af895fda96ef293b177955bdc190e907ec6e31352d1edoc  
2019-04-21 19:26:03b4fdb77c5b6eede55fa1025dcbd522ada24dc6fef82efbeac60934cb6a8e8005docHeodo
2019-04-10 17:10:36006220bd7536e5586c28f4c9f86839c358fd2a75696a4649ff9362de4d1d2c9ddoc  
2019-04-06 21:04:294c0b44452c60ad0812c2a9b659c0556caf992d5d08e23e358ee587a902ca05eddoc  
2019-04-06 21:04:278ea780f930ece3b09e87858bed9a646a9711eb328beca3d121684c2f48ec9deddoc  
2019-04-06 21:04:2757bc53c79977b05fc24521dc9076e5565a69743d0928dd566af51898eb179b2cdoc  
2019-03-26 01:27:56b8b94da3538cbad6e17293c9b76d7d57bcda50a626c13d4dbf62751c9acdabf2doc  
2019-01-03 02:00:042fb1e34572f8f248a459405f29ac485f1ede9ac8607ec9e9aa4201a399548a2fdoc  
2018-06-28 06:31:13ea73652fbecb0539e46da02cb1ef6a9570f37548ad166d4c59af77bd3982bc08doc Heodo
2018-06-28 06:16:15ea73652fbecb0539e46da02cb1ef6a9570f37548ad166d4c59af77bd3982bc08doc Heodo
2018-06-28 03:41:247694066b23ea826ba0367777fe1f3e1b479a7fe3bac84adab2ae30f171ac1d5ddocHeodo
2018-06-19 06:41:49a8ede5b4e9ad5f52a3c28142fa26a4c2caa2d9bd9e73aead41942d31986e4abedocHeodo
2018-06-19 06:09:34a8ede5b4e9ad5f52a3c28142fa26a4c2caa2d9bd9e73aead41942d31986e4abedocHeodo
2018-06-01 17:10:463803bfbce21fffcf67582832f8292d4e40e2417463b3040e293c1938179ef9c1doc