URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lehuohuadao.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-27 07:50:05 UTC
Total malware sites :1
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-19 09:32:14 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-10-19 09:32:14 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-10-23 20:10:38 104.21.26.78Not listedAS13335 CLOUDFLARENETn/ano
2025-10-23 20:10:38 172.67.135.161Not listedAS13335 CLOUDFLARENETn/ano
2025-08-10 11:02:12 172.65.190.172Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 03:12:32 154.23.252.102Not listedAS8796 FD-298-8796- USno
2025-04-28 03:12:31 154.23.252.103Not listedAS8796 FD-298-8796- USno
2020-10-27 07:50:13 119.45.246.18Not listedAS45090 TENCENT-NET-AP- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-27 07:50:13https://lehuohuadao.com/sys-cache/ed5FfWnoJ2H4l...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-29 08:29:38761d87bcf6f5369f3cf451125ea7a56b683a729b1a4caf4a329bfcf95591d189docHeodo
2020-10-29 07:46:461238adf50fa7010276bea39eb50bfd1915d8288181fdc1a10682755abc9b4897docHeodo
2020-10-29 07:16:166a727c9f4dd9cbd0b46dfbe10424610f304eed108280c8e6bed80618b45fa65edocHeodo
2020-10-29 07:05:344bfdf04e63422e1f2b89b19ccdd74439826ca27342cac0f98e259109043cb251docHeodo
2020-10-29 06:42:364c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982docHeodo
2020-10-29 06:19:0540e1e0d4ba67280ae17c0050feb66bf13f27e271efd4fc91413f8553dcf12a09docHeodo
2020-10-29 06:00:28ed5a9cf9f1dc54e472bd41658cb3f19ec7eafcb34da7257c6407697b879a0535docHeodo
2020-10-29 05:45:09b97d2b5410d55c774746d336facb4fac9b81552a5f84073496d20901af3c5f71docHeodo
2020-10-29 05:11:3022c6a7d49453bcc0cba779dde369eceffe882a0c338e712b6340a144e4697c98docHeodo
2020-10-29 04:58:2717d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7docHeodo
2020-10-28 23:28:582a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7docHeodo
2020-10-27 10:12:137d2f13626cd91555d5f9cbdef3a3c17f832e03fc8dc38afb61822dfa3aa37649docHeodo
2020-10-27 09:51:0236178a3ed3f924fd1a1b08abb9f65e5adc5c7e46ecb8c927f993de6dbabbee47docHeodo
2020-10-27 09:38:21ff22e77b88e0475f28d9a9b2dc4822b61b19e7f15738af59dfe973bc0bbedaa7docHeodo
2020-10-27 09:13:31dcbbbc144f4bffa1f934ff14c9d8a916b19ded7738dfcd1b4f123e3ea73da2d4docHeodo
2020-10-27 08:32:25d7c6815a6c9839cb6e4c7b87dd865a478181918dea81112af9afd68e330837fadocHeodo
2020-10-27 07:50:138f323b8ed745f486d1959a02ec0b57609d3461405014d5a1885ddb8f9d171118docHeodo