URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: legion.com.pk
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-12-22 12:45:03 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-29 13:58:05 199.188.201.179business58-2.web-hosting.comNot listedAS22612 NAMECHEAP-NET- USyes
2021-01-18 21:14:41 66.96.147.106106.147.96.66.static.eigbox.netNot listedAS29873 BIZLAND-SD- USno
2020-12-22 12:45:07 66.96.149.3131.149.96.66.static.eigbox.netNot listedAS29873 BIZLAND-SD- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-12-22 12:45:07https://legion.com.pk/__MACOSX/pT3h/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-12-22 21:21:5740b2276b5f2e54f945aacbc8eec699b0bc7aeccec109305d33d600b96dad5464dll Heodo
2020-12-22 21:06:41fe0b2695942accca37445aa3e6545e85b68ae4daad46ccbad20239d50d8a073edll Heodo
2020-12-22 20:55:23cb2183060c6b48cc7538ddb4ea5223e6d74576179cf20b87ded4dae867822565dll Heodo
2020-12-22 20:32:31a6bca1c82c49ab44fee2db8b5052e05a507af1bbad94f58a73cf558ab7d5b36edll Heodo
2020-12-22 20:19:02bca150bd60780f63698ed16efe5d885ce01d914696669f606f2a193edfe202c1dll Heodo
2020-12-22 19:58:199f0d5b65d77f6c919636443b10370bf940890017a923d3252a5b9fedf2ba7767dll Heodo
2020-12-22 19:52:19f4ede79d7ca3d2ac114b6b304da315b14d5322c8dccb2e4c158265dd6e6fa463dll Heodo
2020-12-22 19:27:5642347ece3986b8ece2fce05ab05feeae150fdc88d40944eed61b6b3c35e2a696dll Heodo
2020-12-22 19:10:05bdeb2c7ddebefa92ebfbda70f9de9643e3245e1cf4bc087e938be02aca13a3fbdll Heodo
2020-12-22 18:53:08b9ba14be0fe830210289d9fdc2b083bcb8a4dcf056717a454889cf91efe9dd6ddll Heodo
2020-12-22 18:46:46e336d7cdc6ac462146fdcc741850ff092b2eedefd90e7a14c468542bff9fc41edll Heodo
2020-12-22 18:26:1192f2db9df9429589a07b0600c19b353ca393d4aeabf33e3699c873ce4acd9906dll Heodo
2020-12-22 18:04:599712af0fa9920d38b8062e2dd199c29664f647534fe65566c54c8cdc42e58de2dllHeodo
2020-12-22 17:49:244890a9dcd00608537b8b50669b1fc2a2a29e71056f0bae4d0cd4b0782b6ec9bddll Heodo
2020-12-22 17:33:47c79726a36b8426265465faa8ff15d024a932c836457f583d3421aabf465e4500dll Heodo
2020-12-22 17:14:345085e7cd7ea308adf38d095a32206c4e66fa2fd5faa6ccf8845aa3b08c8d3d46dll Heodo
2020-12-22 16:27:38fde242df421ba254c475a960ce92d7eaadc4dd3f55a5bcafb77e6d79da7a24a1dll Heodo
2020-12-22 15:52:4714fbf21b4dae36e7aa8b60d1abe4f46dcd5bebc8ecdc42db5a1bae688de8c189dll Heodo
2020-12-22 15:27:5452a94bcb0365183ab2d4722002673d5d1867a7e375cf3bd2978489f0d4ad986cdll Heodo
2020-12-22 15:00:09653c6b6f0f83950660be5b44516901b7950f60680e89c51ce8de050ec394dd16dll Heodo
2020-12-22 14:30:5249742453d054e78f93b9fe33661029a0551a59dbbe1703685c08f92774df6e04dll Heodo
2020-12-22 13:46:47217255141916470a566a7bce1a8eecac051896268415b59c73ebe0481c31ff0bdll Heodo
2020-12-22 13:36:11ae1e8a33f7f1d418d3c98b541e93e6bbcd457b238bda606a0bcaec5469cb2456dll Heodo
2020-12-22 13:22:2227beb99c5d74056c04b117b1fa28fc26a7a11c238a06348c7eb75011eef53ac9dll Heodo
2020-12-22 13:08:4618cf53e4dadbfe6b37d0f7214bc093d5e2541c8cc87681bd3964a61fcb8275bedll Heodo
2020-12-22 12:45:063a16361548e0e37ce25163437dc59dc7134d8a1b06c0e88e7f3a74c0314a17e7dll Heodo