URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: kf.50cms.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-24 03:53:04 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-01 02:55:14 43.228.77.237Not listedAS134765 CHINANET-YUNNAN-IDC1- CNyes
2020-01-24 03:53:06 123.206.119.229Not listedAS45090 TENCENT-NET-AP- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-24 03:53:06https://kf.50cms.com/addons/browse/9qskmac/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-25 09:12:1834aa6087e68b3ce662e6557691a32813facf9d5a8b055940a76193565f6473d4docHeodo
2020-01-25 07:52:50ab9fd616c8559e27d691f8496980521027d89f8ce93dd4a9d36e97acd15cb09adoc Heodo
2020-01-25 06:36:4106c3eb09c595f155b5ae5b2e8ac7def23fa2071d4bff2bc2971f179f13af8ef8doc Heodo
2020-01-25 05:54:341247e7db8d37dfef07705aeb3246978c3aa8a27727d0cbb15f4f439275f22e93docHeodo
2020-01-25 05:07:10f2bbad82ff33684373581a995366ff658e8ef182f0429ba7b3bc02c407f5bb76doc Heodo
2020-01-25 03:36:0792f9fc62eada40e103255379d9cada21ecde4872e2a831693013931114092d00doc Heodo
2020-01-25 03:19:43703a5bbaaf0748bf5d322069f6827547a9436c3fd03f4a2ffcfc709d47489049doc Heodo
2020-01-25 02:28:06c14d937dc4e0b3887adf845313fad5e4dcda9f891802606087dbd8eda07ada20doc Heodo
2020-01-25 01:27:14a3d7b01446bfb5f062098c68a00c1bd211e610bc191f04a20e751c5140a8478bdoc Heodo
2020-01-25 00:26:1528a279c154fc7ab9b592169b72ad25533b8f32a666684d67970c20d33ebebef9doc Heodo
2020-01-24 23:52:40c2a344d3169e00358d4ffa41b76a5acc70e2db611f2c923a5dcb1d7d59e8ea06doc Heodo
2020-01-24 23:25:03ec1f5c0ff3763fe4d47fa7ac7c202a880b346e9ddf76590b4c3f6a94c65c2cf4doc Heodo
2020-01-24 21:54:02e0eb5c2414cedd2eb2e4ab88353a5ec141b0fe03459be273d0bfe2239c066b07doc Heodo
2020-01-24 21:04:23edf548758aeb6af93728a0d059f365608263d4677d096d5c0c826a221de425f0doc Heodo
2020-01-24 20:51:19724a5541c2dcfa538c7d02e7780bc282cd11b6a24d622368357e21d2889bf4bbdoc Heodo
2020-01-24 19:37:036c7e00870a13fa54a02ddacd69c4c9e85e9658d161b547faebe94f9c6d17da70doc Heodo
2020-01-24 18:05:54e837e7ff90ea4f6069c540366bef669099d5dc56c8ec0bf410f18ac21295ed02doc Heodo
2020-01-24 16:55:57ef35779e78057ee046358ad2cb091e78e75c0fa76d19134c11f35fff9f906ab1doc Heodo
2020-01-24 15:36:38cba73ededc4676a3fd5ea386a62854670752212eedaeea52fb505d3fb96068fadoc Heodo
2020-01-24 15:22:35be0a76b775c492de0e64927a76fb8aae5bd0f8b6dfa606c3d83ebe1af54ab8d0doc Heodo
2020-01-24 14:05:35e848ede38876ef2dedf485fe2818f53dcfc4a4cdd21062ce8ff7a53d2f8e32b1doc Heodo
2020-01-24 12:40:09789f39cce8f34ef92a1114d703e66a8894c7d3025572c148161fa467d1b6fe81doc Heodo
2020-01-24 11:07:54f0f981739b129260f4ce49dd2f8d7c2f60b9d821aa3e423f6dde6da50580df0bdoc  
2020-01-24 09:36:5555610cd8f35d79fc7997da45e22ce4fb1cb88e0a9a26d1b826101815cf25754bdoc Heodo
2020-01-24 09:19:19f4a53a42cbd4bf3cc4315612164dbc190c95ae5748fc6188b1267b5729952617doc Heodo
2020-01-24 08:05:59e767869c387d6176cedcc00bd0ff08ba017f2f78a5244aa0ca510fd2129a2e3edoc Heodo
2020-01-24 06:33:30907a6b87768814cbf5b5e0f3f1309013bc451d847c150fe7cd2cc6e99ef0c662docHeodo
2020-01-24 05:23:29bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bdoc Heodo
2020-01-24 04:13:304a4adebca656caf3c9f4f0d9dcfd3b4dd73ab412fc73e3c40e3fa94b5d21e270doc Heodo
2020-01-24 03:53:06bf169a1a3ac9d25e038e3074b0275663fdba863c6a0371befe5e238eae107f9edoc