URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: medihub.pk
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-24 00:44:36 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-02 12:06:30 46.28.45.44Not listedAS47583 AS-HOSTINGER- INyes
2020-09-24 00:44:38 168.119.16.147www.netcon-consulting.comNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-24 00:44:38http://medihub.pk/cgi-bin/Overview/n86omqmlv/lf...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-24 12:32:052e3f0cba76c76de6beb1d7782576c1913d7a5ec9e471a36bac04827d26b0185ddocHeodo
2020-09-24 11:46:00fc98a386a0e52834ae5dcb93beb5aa33305f3e71cd4183a2e47c7c38d9cfeb1cdocHeodo
2020-09-24 11:24:175c7bfd1823b37a4f48ff0166d60e88e0be88ae562cf87c6bf393597da4fd835bdocHeodo
2020-09-24 10:35:02d9e5e99a04e37db7783f369c532e2e6d5171b90a286f2c397fcd6356a1abcce9docHeodo
2020-09-24 10:21:3835fdf71d1156a709edbfc6250568a61a62afb183218e5fc5ffc1249ab07bb4b3docHeodo
2020-09-24 09:06:42c7f34900cf5584e0e90f2f5d2131af15abada7eb92f4c9bcdd9f9d8560dbdf46docHeodo
2020-09-24 08:36:34573cf8b0e537a825c17e7f74be98dc2516d0b509eb22cc7a259717e53d50ec53docHeodo
2020-09-24 08:08:1384d837274cbcc7fea7d1806754185fecba6c90d352208ed2c444996864073135docHeodo
2020-09-24 07:54:20e009e8425fa0d5b45b611b840745257948eb8d154a75046329e7bf699f3a60d9docHeodo
2020-09-24 07:45:029530d202be6692b15721f936a6cd20a7319a5dc92e97e12b532ceb3d74641753docHeodo
2020-09-24 06:55:3304c40043a6f85ced583227c163faec46ab1ea268357293dea65e35744895955cdocHeodo
2020-09-24 06:36:03eb7751cd57d85eef7c674547d3a40c0eb9758d9b893fca13e639ac5fbf0fd39fdocHeodo
2020-09-24 05:50:23d522d2f16aa3e16dc127e4340ff8bfd23ab4de894995c8dbb75b31bd4b4d73cbdocHeodo
2020-09-24 05:32:29a92c46f200df0158c9798071b11a95d81eea54126f75084d6b9b381d992d4d0cdocHeodo
2020-09-24 05:02:4119cb69cbc19879e5cae4e56b1d702cfcd04c72ebf8a9c795592d509a91e5a2eadocHeodo
2020-09-24 04:50:11600c433856179a39c24e978c417634772d605b733afea857de865c8ff787105fdocHeodo
2020-09-24 04:18:382ec5659b0eadb3f644298e5c297be25451dff898c0551365d0d757a4e5975556docHeodo
2020-09-24 03:54:087aed739ebb48064d94fa17f51816a7d3f4414ec8d578a6bde0830e844055e971docHeodo
2020-09-24 03:22:158f054924ac0e3a72b2725a18206bf1e2faaa327460d2e7199b1152126241d054docHeodo
2020-09-24 02:51:4694a60a6851a52d97e35329b2b824437bf9dd5eeca3fd759e15f444e217f39635docHeodo
2020-09-24 02:36:518c2167e0297ffcef1e67f0aed9f87dd7de95a4b552865584b7bd0185ac8f98f9docHeodo
2020-09-24 02:03:1780bbc6addbc3d97abecb341c4441b7963d70a2a863d25cf0d35137632a841fa4docHeodo
2020-09-24 01:37:23a26964e2d826f555642d9dac0e19c5bf685767b5a0cb12d9a83e6d332251b17ddocHeodo
2020-09-24 01:31:57098e0c52d47feef3ad6ad20535919541c76799f4bddd67233049509a0ae8656ddocHeodo
2020-09-24 00:44:37a6bdea3758ccb519e3736628a467290a74b47562f8a489e89346642276c9f177docHeodo