URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: jun.web.id
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-13 11:40:25 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-12 10:47:15 103.196.152.177ip-177-152-196-103.wjv-1.biznetg.ioNot listedAS133800 IDNIC-BIZNETGIO-AS-ID- IDyes
2025-04-27 13:02:12 103.152.119.134Not listedAS140443 IDNIC-HERZA-AS-ID- IDno
2020-08-13 11:40:30 103.20.190.60dara.empatdns.comNot listedAS45731 ARDH-AS-ID- IDno
2025-08-06 16:10:19 103.253.215.19Not listedAS58487 CRI-AS-AP- IDno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-13 11:40:30https://jun.web.id/files/MBpSS/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-13 18:54:155068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642edocHeodo
2020-08-13 16:31:479c555a84e2b325b4c2d60e9dba477c087791380312f4c5c664d3ab4f1c47ab86docHeodo
2020-08-13 15:20:07e2b52ca08d4008fa9685112c5dfd20fcc5fb9d70c23426f9a30404ece51ca0d1docHeodo
2020-08-13 11:40:30335ffaa3c9914aabf84fec4cf13a891465b4c0c3700777b1fa2877df708b4c7edocHeodo