URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: jtreus.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-13 10:30:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-17 05:45:54 104.18.52.186Not listedAS13335 CLOUDFLARENETn/ano
2020-08-17 05:45:54 104.18.53.186Not listedAS13335 CLOUDFLARENETn/ano
2020-08-17 05:45:54 172.67.177.155Not listedAS13335 CLOUDFLARENETn/ano
2020-08-13 10:30:06 167.71.231.189Not listedAS14061 DIGITALOCEAN-ASN- INno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-13 10:30:06https://jtreus.com/wp-admin/balance/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-13 20:35:328c688ed47cb4c03e6a851c42d6c0fe9dd9c9e2bcdef1f0884fcac5d2923cf59bdocHeodo
2020-08-13 20:13:269be561c7cf40dc53dbba36e51b0787a5dfb2c43000b0c5915df93ec5ef170687docHeodo
2020-08-13 19:36:097b99b98d51fbd00badb479a3ad6e932681f26678e6749ca34706b8ce2b610400docHeodo
2020-08-13 19:20:5615e32f7a4675db4e399e6ac32e7b9b98197aeb89dc371330c21678abcbe13262docHeodo
2020-08-13 18:54:19bbbfae57148d4ae3803142303babc3d2fcb182194f9112aaa34b6f4978e8e0eedocHeodo
2020-08-13 18:14:38d2096169d1212457db40e6a605d82b82aea4ba2d2ea69225cdd2c60cd104bcd2docHeodo
2020-08-13 17:50:07a4d0b1c2b75f14515784a678a437ffdd8b5542fe3c2d738cbe7bcde2d5b15e0ddocHeodo
2020-08-13 17:22:48f959a3ec8067a6967f047b19554210234638a6ac9b0bac85e006979f09c33d11docHeodo
2020-08-13 16:53:1981c7769a0b7529af3a8694dd0b1141ae2446ebc681026ae67653753eba1ed6b6docHeodo
2020-08-13 16:31:43d567a4097feddecd5e5cabcdde2f997521126535222bec36e0514da36a9886b7docHeodo
2020-08-13 16:18:545f13b204f1454bc08133eb8207a0bbd3faa357d80495f1136ff43768e69914e5docHeodo
2020-08-13 15:59:031d76d6caaf25aedb9a6b4a416eda1a0f237ef09b5100d844a54ed3290242e251docHeodo
2020-08-13 15:31:483d9b7dd248282da644efce8e11e6933424e766ba770a6c0eb2f817b312367a1edocHeodo
2020-08-13 15:08:568a0a74b31fb30ce1a4adbaa3945c4186c7d467268e76b9ca802905b7cf5fa54edocHeodo
2020-08-13 14:45:3573b34aebc917f7437b48467815608b544f747919a4a7e78d4324a99efb030028docHeodo
2020-08-13 14:13:064b99e8df8f724bfea2f32a9274cf4aa0f41b3e57a2b1ec753b17514149c670b2docHeodo
2020-08-13 13:51:1172b00575d9b7dd295462c482d9ee8edfc44b184f3af563f0a2fe49014d824121docHeodo
2020-08-13 13:24:51a8786f3ff1ecf32215198afb54ea5211a0c5fc6468cef97101a85ff5839b05aedocHeodo
2020-08-13 13:03:59ae0c7dfa89cf0301b64ef4f6b364a1e426c79c80a9d0943916c93f3315ebc907docHeodo
2020-08-13 12:48:3311115387b71ec2162713a34b3ced799ace3def99ab9e495234326a68ae1f6ef9docHeodo
2020-08-13 12:31:49430d07c2162af45022115ce4b557ab182afc95143b698568d50c41832c6b281bdocHeodo
2020-08-13 12:11:09e9a1e08c1d8de096fd30cfc93c23d0037c4016bc7c4cad64c8c4c7b6fb3a717bdocHeodo
2020-08-13 11:53:270c4015de45653ee2f8fc6e338461a2377e14139b1ff879df5a2fe1d3c200a15edocHeodo
2020-08-13 11:22:56fdf714d8a02549739b60c414ff535944cd2b7d8a84e465b55f4fa263680e9cbedocHeodo
2020-08-13 10:56:28f1194d491ba7c0f8f39b1c0b9d47c4324742b324adc2e4a3feba13f77e9b40fedocHeodo
2020-08-13 10:35:053f9f641892bac263ede86f11632b4a6498dcc2b94b13727c5dc8c8c594e0f608docHeodo
2020-08-13 10:30:05512f2b47de9367605f5adf2c1e62e8ec8b8a11ae87b5d347d720066f380367e5docHeodo