URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: margaash.us
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-14 20:46:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-02 16:06:16 192.64.119.75Not listedAS22612 NAMECHEAP-NET- USno
2020-10-14 20:46:05 34.92.23.191191.23.92.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- HKno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-14 20:46:05https://margaash.us/sys-cache/DOC/0u9thggdtv/1z...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-15 03:19:32f71ae94d242b3462c842f1437cae8812ed520d8707566c04c3570859cc609937docHeodo
2020-10-15 03:05:3497facc45c64f326ed17ae9ea249dab0f4d6bb4a237092a7996d8e4eaf43226c0docHeodo
2020-10-15 02:31:060cf59450f4af8123dc62d34cb387c1f4bcc5a3c38cd4c966acbd7552574d9fc8docHeodo
2020-10-15 02:21:34100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533docHeodo
2020-10-15 01:47:51fd12780ca0e4c591da35bf3d215c22a47050b1a68e524ce4d0434ee2414cbf3adocHeodo
2020-10-15 01:28:012d22c090ca32c456c3d88c382392a124bf484fb67ef5737c1e9c6ed81b87e4fddocHeodo
2020-10-15 01:15:011790c5fab1f40df300b33f400baa6f3981447142c4368a43e01a5b76b1beed3adocHeodo
2020-10-15 00:56:50275d247b675319a0e083b29b0e1c88b3bae28687e80b83a5b6db109ae72d954ddocHeodo
2020-10-15 00:19:10f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5docHeodo
2020-10-14 23:47:297b075ad4950850227bed02d8388e00fb244191c6f5dc0af216109799e512aa5bdocHeodo
2020-10-14 23:30:479c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811docHeodo
2020-10-14 23:22:350d6731404ab523678e4e70272959a38c04c12861e5d94284b88316c3830f0b9bdocHeodo
2020-10-14 23:08:03766cbde7ddad3ff7d55d13146e76bdfdd1699d56ad5886d619dc2e74f2889d1ddocHeodo
2020-10-14 22:50:539670351cda3385021054e49a74fab0df1f24d4e7d1344baddab81bfc1a4ae963docHeodo
2020-10-14 22:36:07dc41f5064696331607d50440a2dc8ad1aeb74a70cc6d1fe6ff652dc36d48a51ddocHeodo
2020-10-14 22:15:01d8e8296e8032721412eeedd5ef9a8e7c30015865ebfa1b8661f447ff4fcc676ddocHeodo
2020-10-14 22:00:43092bcc5907112bacab3f65e2a0d921eacb8f10f66e7d5ba3346b672f7dfbf165docHeodo
2020-10-14 21:28:2311ee22195d00d98a48b0b0bb49583f59637f52911410fef41176fc8e466f0c88docHeodo
2020-10-14 21:16:5447d2663f2d97a5313bd52117865a0fc284bc8b3c8ebc176fb27d2ed5d60b208fdocHeodo
2020-10-14 20:55:48ac443ee3def6c35248d2c3e6191d6d342a8f45654bab23f50b208062be1df2efdocHeodo
2020-10-14 20:46:05b356139efe926c881eff89255d16d5e8a0364aed9b05d34c491d8515710b3e72docHeodo