URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: novaflon.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-22 16:25:04 UTC
Total malware sites :1
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-15 01:59:10 104.21.53.230Not listedAS13335 CLOUDFLARENETn/ayes
2020-10-22 16:25:05 172.67.219.124Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-30 12:52:16 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2025-04-30 12:52:16 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2020-10-22 21:41:17 2.58.28.32Not listedAS29802 HVC-AS- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-22 16:25:05https://novaflon.com/wp-includes/esp/8DOR9nFDMu0a/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-23 07:06:54c201dc04bed84411f216935bcad9296fdb3e99daa909ead17006846758dc8346docHeodo
2020-10-23 06:45:220066b1d5dd24b167cf158ec3c464c0fb0a4601c4ceb91b64832e7cc48b0b7bcfdocHeodo
2020-10-23 06:30:26044fbfe6a7af7880a4a79b11351a8b657219c5717280368151dc6564e7b81715docHeodo
2020-10-23 06:16:1002e4ce0981c521bd6a8ca1170e5d7ea8ea35c973d2692d1709b8ecf1db394384docHeodo
2020-10-23 05:48:28a129d723a80571d6c9f4402118e7a138d3ce0439cefeb6718c1e34d246586d51docHeodo
2020-10-23 05:23:4025093bb7528311c4eee9c173590bd55d34e3101eeb80a3c3405eca6bc50ddd60docHeodo
2020-10-23 05:02:29b333f4edbcd85640a50a2cacf9a116caa96e2026f2d2089c90b9c1b72e929581docHeodo
2020-10-23 04:41:56623493fea7d7d2f6e25e4e0c6d64d8bc684086cf8258e543f4a859b5e2080eabdocHeodo
2020-10-23 04:33:0588ede93bbd015607192a96718235dc0b427a8f654bec3ea00739a51abf19e5e0docHeodo
2020-10-23 04:11:23d81d19a33f0ac7b353c71ae0ee3bbc4fe3072d9ac384f22725e48503df8d8260docHeodo
2020-10-23 03:30:46ff799dfe689af4b7f91327702adf9abbf48fdeeae9400493c012692c7bb07cebdocHeodo
2020-10-23 03:26:5096140bee4d720328e2113c59df8157377c933260724ce09f2c7f60927b768f55docHeodo
2020-10-23 03:09:436804dbc9724d112e604b0a8c2fa2bdd8d5067918c5479d73632c6258ff83888edocHeodo
2020-10-23 03:06:1503290ac1a4a631b629b8ee0a0ccbe41e7e65fd76ce230251d8179173865e0e68docHeodo
2020-10-23 02:45:48f2c23af1ed5933cc85de5b485aa560d2b3d51ef80a20a4215d0ac0bdd9d07bd6docHeodo
2020-10-23 02:08:56467cff3339922c5222b7cf47bc2ed154aa32c672291b072854671117da5ee6fddocHeodo
2020-10-23 01:44:3431a1196eff28cc5bc1abf437836a0f46235d224545bd9202c8d4e35743f5ece1docHeodo
2020-10-23 01:40:192c4575f92dea12a74d983f35de5c3395d1372a0a14776a90350250ad0eaa6be0docHeodo
2020-10-23 01:05:414f47d35f875582f23b3901262ec4097e7d11df94dbafce009f1264ff100246c2docHeodo
2020-10-23 00:43:09e4375d0a2ba932718dec66682d272815c527e91c52f8fd834f2b13a199c60e95docHeodo
2020-10-23 00:09:210e1515fd40c1660f0b5e48e9eeed031127aad22126d6f1885b30a198f23559eedocHeodo
2020-10-22 23:56:5974956b6fd8fb8af1c1cd21026338c5e52d19533087ce7d60541ec7180469db1ddocHeodo
2020-10-22 23:18:1828f62c50f215f1330b0e55bee7b904932feafada38268abeb16d0f730205cd07docHeodo
2020-10-22 22:34:455dbc67d9b88e0dd44bf600661d17c5726d09f83034d0d8c55dd65aac85569d11doc Heodo
2020-10-22 22:15:33ff00742ee2e924330820490dd85ef3ebae24558e2aea9bdf91cef583bb047cfddoc Heodo
2020-10-22 21:40:53c6656e0509cd5854abdfabd0f1906fa7514dede0e346333b6bc0805729057542docHeodo
2020-10-22 18:15:39d87198e80fbbe7c94cafb9c521c07837a97b8cab7a6dd1a9160051702838363bdocHeodo
2020-10-22 17:57:04aba2852c2ede40d00712d4f0bf753af374f10fa332d165c7bf62b40803c6b393docHeodo
2020-10-22 17:35:0466771dd18891cf71c857800ab02739c617f933bca489b3e5076092d1b767f876docHeodo
2020-10-22 17:01:465f53812706f7dfa6933f0857792ec822cceb05736e9d6004339eac9f037cd956docHeodo
2020-10-22 16:43:593b02b55c561605e9c0ac4654750d40e7fe6d788636d2368186e5aca8cbaf0b2bdocHeodo
2020-10-22 16:25:05f5ea3c1fdc14d93a641aed549436c491220ccd2571f6bcc627d23ff0c5e37b1ddocHeodo