URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: migra.platsandgo.com
Domain registrar:OVH -
Domain registration date:2020-05-05 11:06:17 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 17:05:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-11 17:05:04 92.222.139.190cluster028.hosting.ovh.netNot listedAS16276 OVH- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 17:05:09http://migra.platsandgo.com/wp-content/WhGS/Offlineemotet ext epoch4 redir-doc xls waga_tw
2022-01-11 17:05:04http://migra.platsandgo.com/wp-content/WhGS/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 01:53:03ca65e9146957f09c7cdbb479666279a91d9065b309e29fea80fc5e3b7bd49393xls SilentBuilder
2022-01-12 01:27:40ecaa8fa10f2e5726552f68f4c691133bb782d791b23c96e2c26b5c4838a00e68xlsSilentBuilder
2022-01-12 00:57:08894ae1ab382fe85d09096d1997f468b8e5f327326c39e15bd1ba47f4c4d2f14fxls Heodo
2022-01-12 00:35:57a196a7f762ccc713b4c96a96ad4d8d50c3a27964758730b87741f65f609c91abxls SilentBuilder
2022-01-12 00:12:361c5ad6e4718ec14f2180c8f047a7867ba5ce9f4498024dd2a4f66974ca1cdfcexlsSilentBuilder
2022-01-11 23:48:3166f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6xls SilentBuilder
2022-01-11 23:19:05429e0de91bc404f5fc886f0618177f5bc49fe0da3940e98426c5d5cd8aed57cfxlsHeodo
2022-01-11 23:09:415c5fd037c414e33a6538da72a5ea4ae89c8dac15b396b6a10e8504a0b5a7ee75xlsHeodo
2022-01-11 22:43:17e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091xlsHeodo
2022-01-11 22:15:3415808d5cf09ee4a60ed9e18d0b403cd762cbf7613246e2cdfa6fba88eb654dd8xlsSilentBuilder
2022-01-11 21:47:09755b4ee15682c5a1e3567c5d710b241e03a8b6ce7080dc3ef0816be9ed6e06f7xlsSilentBuilder
2022-01-11 21:34:51244f3b421f675868b3b87f562c2b307e3f4c3b914d67008406a8f9ed0594b4c1xlsSilentBuilder
2022-01-11 21:06:3777d7199bee787fb17ba47e4461be479b626921734ac55b7b76d42531c3b1a211xlsSilentBuilder
2022-01-11 20:53:531224a3bcb32b16ac401374219c7e304bcfd5eba23875426fdbb6bd06345e9e9dxlsSilentBuilder
2022-01-11 20:30:370dec37edf7d179a139b89569d030dc83a715e5d9a945d9dedc410c3fcdd09125xls SilentBuilder
2022-01-11 19:59:5503319a0f6c37911983650f91c2a01b29eac84b17bd99133626d11d08952ad9d4xlsSilentBuilder
2022-01-11 19:26:44a0a6e55d2714273e7c3866776a187cc320e9bfa5086632fc12ed94db2efbfc3dxlsSilentBuilder
2022-01-11 19:16:157b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cxls SilentBuilder
2022-01-11 18:48:1218e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51xlsSilentBuilder
2022-01-11 18:22:225567612a01ddde62a81334d73dc09a4e0f78d8e552d2686d44eb3e3910ecf13dxlsSilentBuilder
2022-01-11 18:10:40b8600d1365521e1a2f83ae356900d38cf8c44b60594bbe30df2ac04418cd823exlsSilentBuilder
2022-01-11 17:45:3138b51ee1239079bda9d7d55d94ad241f9595a1bad8a9538a140cd3504ce559c0xlsSilentBuilder
2022-01-11 17:27:41a88483cdfd340711d7a65d74a5646e6bc7159a4af250074e0fea6db954177753xls SilentBuilder
2022-01-11 17:05:09f143a56e4d2e67d2509660ca4dce1bc226a21b4eef1f51d7d79e718fdb91ea4dhtml  
2022-01-11 17:05:04d5bad8eeefdb87f255cd4c3aba2c1906d156f3e97a5f4c994f22b275d18d3454xls Heodo