URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mail.treeoflifeadventures.com
Domain registrar:GoDaddy -
Domain registration date:2017-11-13 08:33:16 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-08-24 09:52:06 UTC
Total malware sites :38
Online malware sites :0 (0%)
Offline Malware sites :38 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-08-24 09:52:09 41.185.64.155mml11-cvps01.hostserv.co.zaNot listedAS36943 ZA-1-Grid- ZAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-20 15:02:06http://mail.treeoflifeadventures.com/wp-content...Offlineremcos ext RemcosRAT ext James_inthe_box
2023-11-15 09:46:07http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-11-10 19:15:10http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-11-06 09:10:23http://mail.treeoflifeadventures.com/wp-content...OfflineFormbook ext abuse_ch
2023-11-03 07:11:08http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-11-01 16:36:07http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-11-01 06:34:04http://mail.treeoflifeadventures.com/wp-content...Offlineexe abuse_ch
2023-10-30 12:55:08http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-27 07:53:07http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-22 18:29:05http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-19 16:01:05http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-19 05:45:10http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-18 06:53:05http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-16 16:18:08http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-10-16 16:18:04http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-13 20:18:07http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-11 18:31:07http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext opendir abuse_ch
2023-10-11 06:40:08http://mail.treeoflifeadventures.com/wp-content...Offlineexe abuse_ch
2023-10-10 14:46:05http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-10 08:17:04http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-10-09 14:02:06http://mail.treeoflifeadventures.com/wp-content...Offlineremcos ext RemcosRAT ext James_inthe_box
2023-10-06 13:53:07http://mail.treeoflifeadventures.com/wp-content...Offlineremcos ext RemcosRAT ext James_inthe_box
2023-10-02 17:47:06http://mail.treeoflifeadventures.com/wp-content...OfflineAveMariaRAT ext exe rat abuse_ch
2023-09-30 15:59:06http://mail.treeoflifeadventures.com/wp-content...Offlineexe Formbook ext abuse_ch
2023-09-20 13:46:04http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext James_inthe_box
2023-09-19 06:18:33http://mail.treeoflifeadventures.com/wp-content...Offlineexe NanoCore ext rat abuse_ch
2023-09-16 02:05:07http://mail.treeoflifeadventures.com/wp-content...Offline32 exe NanoCore ext zbetcheckin
2023-09-15 13:33:07http://mail.treeoflifeadventures.com/wp-content...OfflineNanoCore ext James_inthe_box
2023-09-14 03:16:06http://mail.treeoflifeadventures.com/wp-content...Offline32 AgentTesla ext exe NanoCore ext zbetcheckin
2023-09-13 15:14:04http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-09-06 05:09:04http://mail.treeoflifeadventures.com/wp-content...Offline32 exe NanoCore ext zbetcheckin
2023-09-05 05:13:07http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-09-01 20:13:03http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-08-31 05:23:07http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-08-29 06:23:09http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch
2023-08-25 04:39:06http://mail.treeoflifeadventures.com/wp-content...Offline64 exe zbetcheckin
2023-08-25 03:58:03http://mail.treeoflifeadventures.com/wp-content...Offline64 exe zbetcheckin
2023-08-24 09:52:09http://mail.treeoflifeadventures.com/wp-content...OfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-20 15:02:069ef9b4a8ab8366ea77b049febf61fd2003aa90b9b38f5c301bff8a60a0feef24exeRemcosRAT
2023-11-10 19:15:102344d3c9c789a2d8256c9edd1720e2b3496dc4e6f3113f5bebc5b5dbdc8d4ccdexeFormbook
2023-11-06 10:26:291821c32e23ff7a3cfb87213f9299eb280cc0152c4170698ce16c6831b627779bexeFormbook
2023-11-06 09:10:23fc2bf8fa7ad46bda0ad6d97117f3f327b47554c43dd789dd39cc654f5c4dd1afexeFormbook
2023-11-03 07:11:0887770248637ba53e2fd2c65ec24b95659d9b1f2d3af87234601fd720f81d6fd8exeFormbook
2023-11-02 04:16:0509c9f5a39dc3e3ac12127313b688b22672dfc6db5a5acb5d3e9c5b6e257b5c17exeFormbook
2023-11-01 16:36:0746b721c436cd339be63937ca6b9912831af85f8fca25d0e752e900683f073a05exeFormbook
2023-10-30 12:55:08858fa0bb526e7ea49318410817f484fff0bfadebc8da580b27fd73234974fe45exeFormbook
2023-10-27 07:53:07d0cbf22d6b18d9544e3c1488b363c099a29b698205bcca18a7eb1ae1c92d4343exeFormbook
2023-10-22 18:29:0569585ae659cf7e13dd4c48f8d3109c5e219cb37f266a3aed6d0e0aac051e89b2exeFormbook
2023-10-19 16:22:54a90acf50649ea6ac91c9aded346e47bd4a6fd2d8f3d3a9daf8c072ab6be99a95exeFormbook
2023-10-19 05:45:109b9b02ea3c7c20a3b347712178063d70b93f8027bb5c57bd160692fbffe582ffexeFormbook
2023-10-16 16:59:10a38cf104fcc3366e6bcd8c6f947b0c6fe7ee30728a2e72b45e96e9b4b0dac384exeFormbook
2023-10-16 16:18:085918737037d535b7a9d6b8c192404aeda12f21a6637659a4a8c1bedb2c7d219dexe AgentTesla
2023-10-13 20:18:073dffc312e024e6daba1c3ff795a3070682341d9f99bd6e9f103d28234c695589exeFormbook
2023-10-11 18:31:077475dc716905ee9a57aa78bdb02c71c1d22d93c67326ac2eedb0b72ca82207b0exeFormbook
2023-10-10 15:04:136168bfdf30f058beb000e91b1ccdb8e264318f8e311f186245b16b8217787c9dexeFormbook
2023-10-10 09:09:43197619791b979892a3f7a7cabb4314b10b360c67442a2b4f101cef42f6b0f412exeFormbook
2023-10-09 14:02:062e2abfd4db12a9c2377450a9ac0fd7bc4657b235f605d1a14de3e6b5c4b65744exeRemcosRAT
2023-10-06 13:53:073cb93d166196c1400e069fd437153d956df26d587c969c2c1a525874633a1e99exeRemcosRAT
2023-10-02 17:47:06d5845fb6e5fb97ed020ef7affac7dbc381c53b12c8c223fd5f657795bd6bdea3exeAveMariaRAT
2023-09-30 15:59:058b8f90243e714bc9f2f2bdd1a70bd0f884b7915aa7d04bb456603ae82e871e8dexeFormbook
2023-09-20 13:53:580998cd32377cfe6c7692fe81f133383175e31720ef3a39b2bba7d63144445215exeAgentTesla
2023-09-16 02:05:073d5aa422a120da634ebad364a3af6cee0be02a23210cec73bf692bbee545d472exeNanoCore
2023-09-15 13:33:07c33376be06134f34b3b1b691f829a795a1031b7352da70a4a95163ee40f81a4aexeNanoCore
2023-09-14 08:47:040817f4e9a329fa90fba9136d6ba89a75cd7c3e78dffdd4d75f116f18c9610e25exeAgentTesla
2023-09-14 08:14:37983ae7a9c8a9751973adcf400c3e28674c737801f7ce4496b95b56545b40028aexeNanoCore
2023-09-14 03:16:064c47c20fb3e45ebc53361f59b23f49ae5cf6354606de41d2f005d5381d85a209exeAgentTesla
2023-09-13 15:56:249ca9d6ddc8f9426428e4a47a74e5ba83a0fccdd5b4619dffe29dee524e6f53c8exeAgentTesla
2023-09-06 05:32:04f35fdd43f200391be9860788b80f9d33b1da585a4d4d702c94c9d2c3a1861324exeNanoCore
2023-09-05 06:01:25ecc7eaf66af67a95b00a9ed1030b779043987b135e2e09f506b8e668cb33c816exeAgentTesla
2023-09-05 05:13:07829f93089df6145e399f52e4ebd4b227b628fa14f92fb8ce8e5d4eeed4cfaa3bexeAgentTesla
2023-09-01 21:15:29bef28d599ab34506504a92f84c6bdeb2c0cadb3d8aae2ccfe2636c34f2052a2bexeAgentTesla
2023-08-31 05:23:07427672b2d8fc7d56bddca99d8d65ac5e61af99267de7cc27a1986af558257fccexeAgentTesla
2023-08-29 11:43:340967d7e5df647dc25f289d039c84a6c2baec77ae247078e59e100e216aca9147exeAgentTesla
2023-08-29 06:23:0977d3f87355760da8f05ae3184f63cfb87a8130d7afc80b864cda6f6cfc7e52b2exeAgentTesla
2023-08-25 04:39:06cac06bf558c6e2e621b4aa57f6d567d934685ad657f618d8a26a7677420ddedeexe 
2023-08-24 09:52:08fd9173d4873cc064aeaa261931ad15731d47fc009e8dd4f96c157793f8745b0eexeAgentTesla