URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mystavki.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-04-12 14:47:05 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 21:02:26 104.21.19.254Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 21:02:26 172.67.190.185Not listedAS13335 CLOUDFLARENETn/ayes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-12 14:47:08http://mystavki.com/wp-content/PxhW-hTA8y8mS7ki...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-13 09:44:160ad1a288380b66bec4c13428d108845caff4201fc46cb0cddb85e4a314da26fcjs Heodo
2019-04-12 22:56:111019bd7e2c3bb1a5b578d7406a74824051d49e84c13864a73635362e7bcbcb4ejs Heodo
2019-04-12 16:04:07342d4017b56faf093f1130c62a4ce9c2c81ba35b7fdf29a2cfc967bcceef4ed0doc Heodo
2019-04-12 15:33:056daa3bc96882673f8d2d74d77c4be3eff3ae5e7f8267fc4025264b4ca1dc1561docHeodo
2019-04-12 14:47:08cdd0eda8b9d2965ec3d7d53e5677b60dd093d5594acb9b50c5133028d1a89856doc Heodo