URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lingflora.co.zw
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-22 12:05:04 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-22 12:05:05 54.36.167.79ns3143017.ip-54-36-167.euNot listedAS16276 OVH- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-22 12:05:05http://lingflora.co.zw/wp-includes/z4tf6dep1v/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-22 21:01:46838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fddocHeodo
2020-10-22 20:27:277870bb6e747db99efe1cf3586ceffa06734408184572a3d7604608401ae9e2a7docHeodo
2020-10-22 20:05:24799c5537098f4e928a07c4c977fc56f159cc71437f05efa2b2fb6676d89b771cdoc Heodo
2020-10-22 19:30:46892a53376594e2bdf65731771d6e7faa4d36e2d3b95340ac4984ec74536d3604docHeodo
2020-10-22 19:06:507726801f846f3a79f073244ea0ffbfbed6ee847b498b4ae15f94a1dc09489fdcdocHeodo
2020-10-22 18:55:24510f6a8a1701b5399083a1f7805f3d944b330676d573a3d33c1aa0ab3df91f41docHeodo
2020-10-22 18:34:35d2e5fecca0f50a65f669ec7b288a2dfc7058179d08831ede0a548433ed90eb88docHeodo
2020-10-22 18:06:1755e79ed4dc97111eb94b6830fdada156fc8d7ca76f3dc5a15d737fbd0dba8757doc Heodo
2020-10-22 17:26:1464043ad11e076ee6e0b96158f87f864ca48289e112734d2b59678e752d176307docHeodo
2020-10-22 17:08:29a0c3617197a6bcd01ceb39b73663300421eb77c56391c866abab0deba5c94078docHeodo
2020-10-22 17:00:58cda2a4d05c53cff76ef32a29480efec51818dc2f26b02999980a33f1051d732bdocHeodo
2020-10-22 16:41:51b7fca993ba0280a6ae9d376c6e08462489275971b8d09a4faa7194332be65937docHeodo
2020-10-22 16:09:012012a08768e19ce57c0229fe901f5710998a91d936f73c4ca838dab581c5010ddocHeodo
2020-10-22 15:46:471398dfcbea47214d59bb327957bac69b2db7c06a50da13399c63aa797fa5fa9bdocHeodo
2020-10-22 15:11:316f64e8f7b58ef57d185a9150be2954a871855e0c33586a9309652e7b16a333b5docHeodo
2020-10-22 14:45:45b4461b5c2c529cceec7d5f7ca41dae1c6f767b6fb54c560269f4ddd7d64878eedocHeodo
2020-10-22 14:31:0815617c0893da95a3d6a9ef0767194dcdba28768fb1cb5bdd12b8321f99f7b970docHeodo
2020-10-22 14:09:19bd0b9def761b12a874705128bbe806e2e8f316cb6be5eb429ca29791a429e690docHeodo
2020-10-22 13:36:198fff54beb4262f2a56b898c4004613c1f1fd9933cdcd99c0f45ea1eafb125b48docHeodo
2020-10-22 13:04:10d846ca5a520f26f0d6c01d2033a9ad5f5a23deb72df286bc23fa92e4aeadeefcdocHeodo
2020-10-22 12:29:217eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0docHeodo
2020-10-22 12:05:05c41bcade49f3e2413b5d95ce09c2ecf30c21b43ab6b306206b9b737f1cd10450docHeodo