URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: office-cloud-reserve.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-16 08:57:33 UTC
Total malware sites :9
Online malware sites :0 (0%)
Offline Malware sites :9 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-16 11:53:06 147.78.67.174vm2464184.firstbyte.clubNot listedAS204997 FIRSTBYTE-AS- RUno
2020-04-16 16:22:38 45.139.186.1680.0.0.0Not listedAS59504 vpsville-AS- RUno
2020-04-16 08:57:33 95.142.44.213free.eurobyte.ruNot listedAS210079 EUROBYTE- RUno
2020-04-16 08:57:33 37.46.131.116kirll.boy.fvds.ruNot listedAS29182 RU-JSCIOT- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-20 21:55:57http://office-cloud-reserve.com/Scan.rtfOffline c_APT_ure
2020-04-20 21:54:45http://office-cloud-reserve.com/Scan.rtf?raw=trueOffline c_APT_ure
2020-04-16 09:01:10http://office-cloud-reserve.com/2.binOfflineEncoded opendir abuse_ch
2020-04-16 09:01:08http://office-cloud-reserve.com/Attack.jpgOfflineEncoded opendir abuse_ch
2020-04-16 09:00:42http://office-cloud-reserve.com/Projekt.wbkOfflineopendir RTF abuse_ch
2020-04-16 09:00:39http://office-cloud-reserve.com/async.exeOfflineAgentTesla ext exe opendir abuse_ch
2020-04-16 08:59:37http://office-cloud-reserve.com/hydro.exeOfflineAgentTesla ext exe opendir abuse_ch
2020-04-16 08:58:35http://office-cloud-reserve.com/Projekt.rtfOfflineopendir RTF abuse_ch
2020-04-16 08:57:33http://office-cloud-reserve.com/Payload.docxOfflinedocx opendir ta505 ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-16 09:24:391c1130ce3271a9e6274359dff31e8ee2f6c976e6df1e494dfdaac3b8f9a2b605exeAgentTesla
2020-04-16 09:23:3174ab8f0473abd56c9bc966703098259faee9c244e7a0348c0c6adc8cb454d2c3exeAgentTesla
2020-04-16 09:22:55281896c20c9ae01b1a4ddc590c5cec454865cd95aaa7e53aac436a3b89889486docxTA505
2020-04-16 09:01:1016fc9e83e217aa6b8f14a5fdcc23102ec1692998625baf47272255bafc44a61cunknown 
2020-04-16 09:01:082f6282fd33d59f387a459206cf5b25a553563f91776ab47b5339174e8a634374txt