URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: klaksona2.net
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-04 19:04:05 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 01:31:04 31.172.76.106hostru06.fornex.hostNot listedAS48018 FORNEX-RU-AS- ESyes
2021-01-04 19:04:06 5.187.6.135hostde21.fornex.hostNot listedAS44051 FORNEX-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-04 19:04:06http://klaksona2.net/_dump/BUyy0Zaa4VOb1rf8Ff0A...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-04 23:49:01bf2f59ecb85a6029a908bdf90f5dae875e68196bf1987cf72959bd568355c702docHeodo
2021-01-04 23:30:539e43571bf7a712feb6f6f6f2dbbef7876ee0a5895f2219bb76775b6809d98f09docHeodo
2021-01-04 23:14:51e2de08e5eefb901fdc1050f3870f4efc4d9853158f3a93a1db37b2f4b140459edocHeodo
2021-01-04 23:05:04145466e49f1ebf4ed38896709a64733353a2389bd676b7ef055c79637f53c082docHeodo
2021-01-04 22:50:06bd71cb5216319d67b7163d101b227e46c1b8172480c96aee9172be8670c32fbfdocHeodo
2021-01-04 22:40:52ec3397b618b0b92c5556cac23ae40686fe9fca8c6fb2097fe84de3909ae48e1ddocHeodo
2021-01-04 22:31:3070364c0d02f4a1d61a76caf33b3c7b6349e382fc465685ce6ff04f6b1f422b1edocHeodo
2021-01-04 22:24:466a61b4d6424c45621d9da70561c8bb5c1a28772e43241374ea706bb04cbfc058docHeodo
2021-01-04 22:05:147bb94464b3d84793306c5871494ec5b557815c2dee93f5ff5ba01e1fe7c85d88docHeodo
2021-01-04 21:54:4717c93d81b95f2b725804776e87495cb9c024cd0c25c389dbb1931bfe5b335824docHeodo
2021-01-04 21:39:328c09b7c7b59889f547395a4d9d2832a4b32b88e8d5e3bb22bb560842190c58d0docHeodo
2021-01-04 21:17:35ee679637d75a8f5af5112158416276ace0f51e892a1b1bbf0987c2e3f8d366e5docHeodo
2021-01-04 21:10:14e17ab8ab24888272311390fa534231d03447787b2c7f69a691c30b04f9c18c51docHeodo
2021-01-04 21:00:292cc7e1f0bd0691c4398e97ad98573985d7c28a85712210379e667f7573baad2edocHeodo
2021-01-04 20:47:4649a4678f9b33879cb16662dd5d05bc7e7ec713bbf6a85741a81f9e1e0f3c37f4docHeodo
2021-01-04 20:38:02bfb1730113cb5053d74406fb4fef94281848b94a36f77692bfa06724fb26712fdocHeodo
2021-01-04 20:20:404ce9c1ba330aeca51cd7b8f6b7e1796c1ead42dde6868d7a5fd636b9a3a9f4f9docHeodo
2021-01-04 20:12:1182d7ccf8a708facd6356a918e9930803db68740bffed556687da9891ebb7910cdocHeodo
2021-01-04 19:55:1340977b89d6a6667e3e77e68d8a87500fb5461c61c6aaab7355550246e0f03cd6docHeodo
2021-01-04 19:49:26eaa2a7a6ead0fb817d96de5539291d86caf887cbba94836c246755105a7a1429docHeodo
2021-01-04 19:35:40fea083de9b31b49497005d6f38cc508f73e1853f6563eb2775257b8a48b9ff42docHeodo
2021-01-04 19:24:347e6a510852e8b5039c2dc9ea63d7420b5dc842c21c534cf29b343454d726a4bfdocHeodo
2021-01-04 19:11:04ac2433d19823522a5239c92113bcd6b6e9bd92a56465ec572b75490cdbe14ea1docHeodo
2021-01-04 19:04:066dbcc0255f24c2876b32acaea6ac383eb2995ef52d51806db60df781d4b15e54docHeodo