URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nivasoft.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-23 19:27:02 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-13 07:29:08 184.168.96.143143.96.168.184.host.secureserver.netNot listedAS26496 AS-26496-GO-DADDY-COM-LLC- SGyes
2025-04-27 10:45:43 104.21.112.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.16.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.32.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.48.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.64.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.80.1SBL681411AS13335 CLOUDFLARENETn/ano
2025-04-27 10:45:43 104.21.96.1Not listedAS13335 CLOUDFLARENETn/ano
2020-01-23 19:27:04 74.208.236.2474-208-236-24.elastic-ssl.ui-r.comNot listedAS8560 IONOS-AS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-23 19:27:04http://nivasoft.com/wp-admin/FILE/jrdjome-51744...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-24 15:37:026f5b6ce04708712cdb5319ec58f2ebc8ea192e9b229cb5a574ccca831f89f679docHeodo
2020-01-24 15:21:3617d0af0278265e68fc7bd551aea53ca47aea8455884650d045407cbddf0d0b96doc Heodo
2020-01-24 14:06:23e848ede38876ef2dedf485fe2818f53dcfc4a4cdd21062ce8ff7a53d2f8e32b1doc Heodo
2020-01-24 12:40:34789f39cce8f34ef92a1114d703e66a8894c7d3025572c148161fa467d1b6fe81doc Heodo
2020-01-24 11:08:33f0f981739b129260f4ce49dd2f8d7c2f60b9d821aa3e423f6dde6da50580df0bdoc  
2020-01-24 09:37:39a73762a4fcac6839eb5266cc79c7363b551e6bd22d63e2ca84f916607b32f0f9doc Heodo
2020-01-24 09:18:24f4a53a42cbd4bf3cc4315612164dbc190c95ae5748fc6188b1267b5729952617doc Heodo
2020-01-24 08:06:3354d8d084eae914e7fb2b134d6c6a836582279f3a69530cfd9261733b0ca635d2doc Heodo
2020-01-24 06:33:32907a6b87768814cbf5b5e0f3f1309013bc451d847c150fe7cd2cc6e99ef0c662docHeodo
2020-01-24 05:23:33bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bdoc Heodo
2020-01-24 04:11:262c4b0f8d4c1eaa6adbac77b21a05ff32242cab116fc252c21c67fc0ab51ba110doc Heodo
2020-01-24 02:50:5173da5cdf0f98ea4dbedb8219ddd051b4d7a04c9750fc4b1d6f9c8e4f9e218c53doc Heodo
2020-01-24 02:40:242caa93025cda12c41ce7d3ac89a2e81c7db0a40a6571fb3cb406c98e2ec71097doc  
2020-01-24 01:08:29ec1da54265100311f4df396c8990940f8a6ff623eb2544ebb860e0283a23b36ddoc Heodo
2020-01-23 23:51:220722f8049954458b37f5abac8260f73b904d3cc22b749cd8f17136ce6640de34doc Heodo
2020-01-23 22:19:2244383ba280209b37ce51bd1acbbedeb0ce8a381c7df3cae05f3a624b75bad529doc Heodo
2020-01-23 20:57:173a76b7d3240f3344c201177ea0e2b0bd7aee4bde433b53323846bbfa9281b7b5doc Heodo
2020-01-23 19:27:04175b315fde3fed3efb59e38ea1cd0a3a0124341342ac4fd15a3e3b6671aaf947doc Heodo