URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: megapolis-trade.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-05-31 17:39:02 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :27

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-01 14:11:24 194.67.71.93Not listedAS197695 AS-REGRU- RUno
2025-06-09 05:50:31 194.67.71.13Not listedAS197695 AS-REGRU- RUno
2025-06-06 19:29:06 194.67.71.12Not listedAS197695 AS-REGRU- RUno
2025-05-27 11:08:45 194.67.71.189Not listedAS197695 AS-REGRU- RUno
2019-05-31 17:39:03 37.140.192.26vip179.hosting.reg.ruNot listedAS197695 AS-REGRU- RUno
2025-06-14 08:19:15 194.67.71.194Not listedAS197695 AS-REGRU- RUno
2025-06-25 18:18:27 194.67.71.11Not listedAS197695 AS-REGRU- RUno
2025-05-28 18:09:12 194.67.71.124Not listedAS197695 AS-REGRU- RUno
2025-05-28 07:02:03 194.67.71.91Not listedAS197695 AS-REGRU- RUno
2025-06-18 03:01:02 194.67.71.88Not listedAS197695 AS-REGRU- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-06-02 21:24:02http://megapolis-trade.ru/cgi-bin/u9o6mpa4scyrv...Offlinedoc emotet ext epoch2 Cryptolaemus1
2019-05-31 17:39:03https://megapolis-trade.ru/cgi-bin/u9o6mpa4scyr...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-06-01 04:44:12ef62880b29c9e9403633bfe2c0572d75e5d9ee3fa4fb698697dceb9efc99ec3ddocHeodo
2019-06-01 03:58:12570a32b3a97f12b17246e9940817c9c72ee63ac383f6983e342e09f79debb17edoc Heodo
2019-06-01 03:43:36bf032ea596d973c8333c4a7d4e7338cdb4276e3d2e8ae5046b8bfbac20941c92doc Heodo
2019-06-01 02:44:13f5f4295f963a3f3ac6e0dc5f1b965821609ca045e1ee63c8687225310155887bdoc Heodo
2019-06-01 02:17:11e5cd9fb3599e112d7f690ec64cc87eaca100d75fc46123812fb4a690ad71be55doc  
2019-06-01 00:43:081c2f25113cf027732770e9f16c727da8ed92c9503034e0c7642bf26d939a8c84doc  
2019-06-01 00:25:116db3364c302d5c19db16a08c2bc81b3d4c2950d667272c12dcbd6827654aeabfdoc Heodo
2019-06-01 00:01:0811870a8a506caeaea612f915e9f28d865ffc5cd8ebe791584e00584b0a9016eadoc Heodo
2019-05-31 23:39:0849682d6275f2860d0b97b984d63ccecf1268c44ab9a147ddf95662472cd9a538doc Heodo
2019-05-31 23:15:08f8e39ecf6d736e3e321da3e786e095c108564c0ada8a0916f70e04bc642e60d5doc Heodo
2019-05-31 22:28:10f2c59cc9eaffd0c7050123d864febc3e5380b439d1041aaeb45b04ae7c6e6bbadoc Heodo
2019-05-31 21:41:08e1e0d91e131669f5c88bd9a851b270f11c8eb364f13253c1adc7c965db858dcadoc Heodo
2019-05-31 21:17:14779c02f8abcccc5dea6c4456fe0fdf519f7abcc36f2c9ff6d1e1ef934741142cdoc  
2019-05-31 20:31:0814e39469bea5e529217ebf13911d4c03eeba3657b224d187be857903cd4a6018doc Heodo
2019-05-31 20:00:14aa42a5f10fc08dd7b5e163a4e84cdf5e7f8315f53b3cbd258003e4cda1859a56doc Heodo
2019-05-31 19:14:08a53484da9e213b8f9a1506bc4356647f57082f7eddc755737785e30ba2b09eacdoc Heodo
2019-05-31 18:50:098f4852fa2c68ac025463fc858447d51fdcb2d4d7bc4d1ea7987563baf0ca3febdoc Heodo
2019-05-31 18:03:09e5009799562414d49629a271b53611e9e72d6886a79f293f417d75822de62318doc Heodo
2019-05-31 17:39:030b609aad113f8a2764855434f59b78602e012b81d7e7c97807f154116e278272doc Heodo