URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: korseland.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-04-12 16:49:02 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-04-12 16:49:05 94.73.146.10994-73-146-109.cizgi.net.trNot listedAS34619 CIZGI- TRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-15 19:29:19http://korseland.com/ynibgkd65jf/zrWSv-i3urJbAE...Offlineemotet ext heodo ext spamhaus
2019-04-12 16:49:05http://korseland.com/ynibgkd65jf/ewLn-41y1sbkz7...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-17 17:01:066e883cc940754fc1ea7cdc187a5b10b37c41d0bf6fd6d3ce768ae261c67ca2eezip  
2019-04-17 16:24:08ea0414489b28abb5471549bc70317e46218a639b721aa49345c4dcdff946b76fjs  
2019-04-17 10:26:5683cf7d870e2b0dab12e3c03ce9ca846ea71158f2bcc55f11b698de99809219aczip  
2019-04-16 00:41:07e328f1a48cce3e9220c38d847ccea9f81b6135d120bd76b224c4be21405f700ejs Heodo
2019-04-15 23:08:288cd4e36661364ce87f1ab5d766e5dc204b3087c58acb95765dbfeafcf5f43534doc Heodo
2019-04-15 22:21:07da956cc8f7e31477de3ad6df05f775b0ed58912dcf2f4c427d629e39d4f77394doc Heodo
2019-04-15 21:34:077a90e8befaf91ce86dc82bf17531ac6f5ea555d3038a4d1df0618977ec6e1b47doc Heodo
2019-04-15 20:47:18d3c849deebf71131db61d59250660c7da5af5e040bce30d2c9de50654ed73759doc Heodo
2019-04-15 20:10:18d21e54044bead3a0db93cac41fd446fb19d90d1d0baf604d5f6134c710a8b2fbdoc Heodo
2019-04-15 19:29:193bb7d4f4f6f53b750781940dc8f6adf33b45648cb1259764eadd56000bb19f43doc Heodo
2019-04-14 09:14:18268307363c224d65da7370d6da6cf518826f73a2d38cf8174037d4fcc5d18570jsHeodo
2019-04-13 18:11:160e4cb4664c90b327e9cc3da8b12def365d187ab543b6a840b95458913a17549ejsHeodo
2019-04-13 09:44:160ad1a288380b66bec4c13428d108845caff4201fc46cb0cddb85e4a314da26fcjs Heodo
2019-04-12 20:49:091019bd7e2c3bb1a5b578d7406a74824051d49e84c13864a73635362e7bcbcb4ejs Heodo
2019-04-12 19:46:18ee1a33fd81e68eef2c49a0e4b3521bc11d455bbf96fb8360618c6cb120814e85docHeodo
2019-04-12 18:10:0633bce221f8ebe653fde7e60ff88a6965c25463d8d339564d007b5c345c109df7doc Heodo
2019-04-12 17:39:12cc06c02266ac3669408c36ee4827590288b7a7c2dd8e8da7b90e455d25922e5fdoc Heodo
2019-04-12 17:07:1197f2089d292d618ed0bac5e3ea99a8a8c6df456f7d310c7cf3f900c3eaad7276doc Heodo
2019-04-12 16:49:05d1eac6c0e901c9f071abcb3817707194850d497eb63012b5264f305cbd8de52bdoc Heodo