URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: kdthreadss.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-22 15:19:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-10 01:28:20 161.97.93.80ip-80-93-97-161.static.contabo.netNot listedAS51167 CONTABO- FRno
2020-10-22 15:19:04 164.68.110.47ip-47-110-68-164.static.contabo.netNot listedAS51167 CONTABO- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-22 15:19:04https://kdthreadss.com/wp-content/INC/gqnrqgh7-...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-22 23:16:0659235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5docHeodo
2020-10-22 22:45:16f9390045c0aecc111eb3b34d5a18ed0f8a5f639169463735528801c99fad0af7doc Heodo
2020-10-22 22:26:5673afab923f309960ba6ef1f00b4d373abce5e6605b10a2b214ca42b7736f1f6bdoc Heodo
2020-10-22 21:41:288f46672fc4bd13f926555000c39b3ff624d7b96f41429e568aa2bad30431bbe8doc Heodo
2020-10-22 20:44:13188d183f83a1b99f55ae2810384c67e6f7be09014e6004bb5ddbf245abda02b3doc Heodo
2020-10-22 20:30:53a92e9fd1aaea72831f29e20e4afe829f2fd63c7645e2ae3b8b4786a8ade2b0b6doc Heodo
2020-10-22 20:09:44621c80400686860afb16c417aa76f5068c7bcd642104a225644b805539b9e5c6doc Heodo
2020-10-22 19:39:2405c27cabbde0441208b26f77df5a0f5346f2c057b25ab1515c61805324c18ae9doc Heodo
2020-10-22 19:15:139192adc6ad055a6e640fd17c385e4aa7e88fad75617119f2f64efcec5dc4da19doc Heodo
2020-10-22 18:55:13d078837cdc9042641925b36475f87954994b19f05d89c10b4ab4a1ea28a806efdoc Heodo
2020-10-22 18:27:47a53f4bb796189439737207c506acde597330328109ac2d78b693d2d6a72e4ba8doc Heodo
2020-10-22 18:03:512f11fb391c4e5106c86f7af02261b1ce605f84877b62af40538177fc258c9e05doc Heodo
2020-10-22 17:40:349cf25c48f4ec39224ac29cc1f585d0127b85a378dac61c893d5b383577137701doc Heodo
2020-10-22 17:01:31c997bba83eb4e15d19a871e5f4e7f506eb780772858f744dd12742b9c678e897doc Heodo
2020-10-22 16:51:56ea4923d6d51058428ce3cac6ced475b5e024b7ae1974b0ce9f37f563847f89f0doc Heodo
2020-10-22 16:24:4330aa3f0d8ff2254375695811a076d309440d33b009b142827eb9e890dba07864doc Heodo
2020-10-22 15:41:46fe69570cfe43c056f36d0a40929d53d4532cd181924613bda7436913979c33cbdoc Heodo
2020-10-22 15:19:0446035df42146415903e45c8938c23ce819bf83cb2e5328b555ec947a0d1b9bd0doc Heodo