URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: novacasa.com.ar
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-25 18:22:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 00:26:31 200.58.112.156c216.dattaweb.comNot listedAS27823 Dattatec.com- ARyes
2020-08-26 11:38:57 149.56.253.53Not listedAS16276 OVH- CAno
2020-08-25 18:22:07 192.99.99.213Not listedAS16276 OVH- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-28 02:28:32http://novacasa.com.ar/main/browse/uitjg0905871...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-08-25 18:22:07http://novacasa.com.ar/main/Document/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-28 03:57:15d15d207c796247cb72e865fb89b2d86126c3ae9e3f7f84d6d799a5c179fee17fdocHeodo
2020-08-28 02:28:32ea1ce5f9d12c67465b28319cf9b23a41cf938fe17878362a3a58f68bd85a9703docHeodo
2020-08-26 08:11:230322eae38619df582bc680d8fbde3a8a8f4b9e2c02b689db2d863c62f88c559adocHeodo
2020-08-26 07:35:439997c20c3de08d0e953e96b71964a91541de79d10d355506c06c65cbcb92dc53docHeodo
2020-08-26 07:13:25dea98698a907a95e646de347286e7bc23d8d095022a89d3e4dc22b1652eaabaddocHeodo
2020-08-26 01:19:08300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1edocHeodo
2020-08-26 00:59:08ddf500146efb671da13e611911185a3e2e1bdb538e7f41ae0eb759a38adebfdadocHeodo
2020-08-26 00:36:25a4b0033aace38e2c6d2dfadfe6776527459551c761c232558d3c573220f5c15fdocHeodo
2020-08-26 00:17:134014edeacef628a8e6b950feaa547a482a43162461571eb152266564c38c619ddocHeodo
2020-08-25 23:57:0469c3e163903f4fcf7f5a52ccc3ba9d74d72c246208f4850abffd01971a51e795docHeodo
2020-08-25 23:37:20966e05abf8db8638c7e4ca88db7b7943092c05b18f44597801128b6f7ba41254doc Heodo
2020-08-25 23:15:58b1e3c18649bc4cbed912ce7f0087cdba73298204214713ad1038375ad055142bdoc Heodo
2020-08-25 22:53:30a60bfe31dcab8ba0730c4edb7de14a10147c618560d09a6137b8e7bb6209dbc1docHeodo
2020-08-25 22:31:111cfa8b0347632b49a79619381b1d4e69a627df9cc64c67f825d774937ccb28b9doc Heodo
2020-08-25 22:07:49edc3477618d76e98889e1be29182a8db3e21ff561eaea309e12070219788bab4docHeodo
2020-08-25 21:53:292eeec2892926e686de8fcc29fc57c57b10a4f37e49cee06ec4b5c864dcf5cfbedocHeodo
2020-08-25 21:43:32c0bc03edcf17373ca7bcc145fddea1578f8998fb6f1d400d3701ebbe4ac1c833docHeodo
2020-08-25 21:21:520d20df2cfdf9cf06ae715303485715ec9bf9baf96fb9e6a9f7de0bd43479e678docHeodo
2020-08-25 21:02:0352d5f65c1708917e116f0217caac8d2a8ebdc93b3b349f9f42b7d7c1b13d69d6docHeodo
2020-08-25 20:29:3896eef74c59d9b8b47979fbaf2552a9735dcddef28df0b5b87655a4c849f9d853doc Heodo
2020-08-25 20:02:52c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266docHeodo
2020-08-25 19:38:23ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebdoc Heodo
2020-08-25 19:22:095419b1d842aa8d13493c5ac67bfd2839472947b3345c2f6552dc69521575959fdocHeodo
2020-08-25 18:59:402005da08cf5f5e5489e2eee91a32b61ee7c2da83fcbd47f566eb7a3a29388151docHeodo
2020-08-25 18:38:05cd5de7d65b2e9b1096050ce5dc17eab61c74558a8570d384af33e78dd2d9b025docHeodo
2020-08-25 18:22:07b860f1abc824d625bf41ccd7b4253b41b9c359fb8027708d8867ba47ad7e98eedocHeodo