URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: office-archive-index.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-21 09:01:32 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-21 22:02:10 45.143.138.118h4ckit.ruNot listedAS47196 Garant-Park-Internet- RUno
2020-04-22 14:35:40 185.14.31.113Not listedAS21100 ITLDC-EU- NLno
2020-04-22 10:58:17 81.29.134.80host-81-29-134-80.iqdata.centerNot listedAS12555 IMAQLIQ- RUno
2020-04-22 08:54:19 92.242.40.54Not listedAS49063 DTLN- RUno
2020-04-21 11:49:07 45.143.138.53Not listedAS47196 Garant-Park-Internet- RUno
2020-04-21 13:19:46 5.34.178.187free.dsNot listedAS8254 ROUTE95- USno
2020-04-21 09:01:36 91.215.170.228reros.bizNot listedAS49693 BEST-HOSTER- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-21 18:02:17http://office-archive-index.com/Attack.jpgOfflineopendir p5yb34m
2020-04-21 17:58:09http://office-archive-index.com/Scan.rtfOfflineopendir RTF p5yb34m
2020-04-21 17:57:06http://office-archive-index.com/2.binOfflinebin opendir p5yb34m
2020-04-21 09:18:13http://office-archive-index.com/Payload.docxOfflinedoc ta505 ext oppimaniac
2020-04-21 09:18:06http://office-archive-index.com/Projekt.rtfOfflineRTF oppimaniac
2020-04-21 09:16:12http://office-archive-index.com/tesla.exeOfflineAgentTesla ext exe oppimaniac
2020-04-21 09:16:07http://office-archive-index.com/putin.vbsOfflinevbs oppimaniac
2020-04-21 09:01:36http://office-archive-index.com/Scan.wbk?raw=trueOfflineRTF oppimaniac

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-22 07:26:37927f4431ccbdcb6a1b5751440ca017f8bce92ae1b5a6ec676bc01fc444f760dbtxt  
2020-04-21 18:02:1719879e2cab37da9391f9ea806ed28f1eae95da2d4fcdd5c2bea76da9d604b853txt  
2020-04-21 17:57:0616fc9e83e217aa6b8f14a5fdcc23102ec1692998625baf47272255bafc44a61cunknown 
2020-04-21 09:18:13281896c20c9ae01b1a4ddc590c5cec454865cd95aaa7e53aac436a3b89889486docxTA505
2020-04-21 09:16:12b27fd2cbe483e550851bc677136273b638ca49ac2bf58e64e51ca1db6763f387exeAgentTesla