URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: office-updates-index.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-01 08:54:03 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :13

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-02 07:27:48 91.215.169.52Not listedAS49693 BEST-HOSTER- RUno
2020-04-02 16:09:13 95.142.39.15vm559882.eurodir.ruNot listedAS210079 EUROBYTE- RUno
2020-04-02 09:26:55 37.140.197.3937-140-197-39.cloudvps.regruhosting.ruNot listedAS197695 AS-REGRU- RUno
2020-04-02 07:27:46 37.230.115.190uffu.siteNot listedAS29182 RU-JSCIOT- RUno
2020-04-01 22:26:42 82.118.22.138Not listedAS204957 GREENFLOID-AS- PLno
2020-04-01 18:29:47 193.32.188.169free.dsNot listedAS50053 VDSKA-AS- RUno
2020-04-01 18:29:44 89.191.225.200Not listedAS211183 AdminVPS- RUno
2020-04-01 16:15:19 95.142.44.187vm376988.eurodir.ruNot listedAS210079 EUROBYTE- RUno
2020-04-01 16:15:19 89.108.65.107mixtop.ruNot listedAS197695 AS-REGRU- RUno
2020-04-01 08:54:05 31.41.44.175free.cishost.ruNot listedAS56577 ASRELINK- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-02 07:46:27http://office-updates-index.com/max.binOfflineencrypted GuLoader ext abuse_ch
2020-04-01 09:19:33http://office-updates-index.com/Attack.jpgOfflineEncoded abuse_ch
2020-04-01 08:55:04http://office-updates-index.com/front.binOfflineencrypted oppimaniac
2020-04-01 08:54:11http://office-updates-index.com/Report.rtfOfflineRTF oppimaniac
2020-04-01 08:54:05http://office-updates-index.com/File.vbsOfflinevbs oppimaniac

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-02 07:46:2537f0846404ec9156d93c1eb3870d9055174112454b79fae7f5f877ce57cacbf2unknown  
2020-04-01 09:19:3348886181c00938bf03eedf0c9e5b0ddd9ef50af41d36a72f2585f0fbab0e76b7txt  
2020-04-01 08:55:04b0cc6f5f365f2afcc63468bdb6515db165c299aa5354c5124a20636588b37e85unknown