URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lunaandrodinpublishing.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 16:39:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-03-12 12:56:01 34.231.102.194ec2-34-231-102-194.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2020-10-21 16:39:05 104.26.8.161Not listedAS13335 CLOUDFLARENETn/ano
2020-10-21 16:39:06 104.26.9.161Not listedAS13335 CLOUDFLARENETn/ano
2020-10-21 16:39:06 172.67.71.91Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-21 16:39:06https://lunaandrodinpublishing.com/alfacgiapi/p...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-21 18:33:301cbfe4acb45540cc1c03e93696d3c85a5ce3162e105d69cbc2c24f6b468fba90docHeodo
2020-10-21 18:03:284cfd922ccbd3d6027a2ebbb689c57aef09cd59c0b24825098d1b51868e989ec7doc Heodo
2020-10-21 17:34:142776ddec53bb1fb2deabfd3bcf61453c5f4f74c077b563b634fe985b43751befdocHeodo
2020-10-21 17:01:229f892449d9dd2097e8a1fffc51fb03215b306bc4cd0d8a1399d936a0cf4477a2doc Heodo
2020-10-21 16:39:05c6ff49b3bc2ed6e3e775a15431c71f5264799248321b4a95fbb2039da227c729docHeodo