URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: office-updates-indexes.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-02 16:59:03 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-04 18:19:30 195.123.224.153xo20.comNot listedAS59729 ITL-BG- BGno
2020-04-04 18:19:29 45.143.138.24Not listedAS47196 Garant-Park-Internet- RUno
2020-04-02 21:48:21 46.16.13.223Not listedAS50340 SELECTEL-MSK- RUno
2020-04-04 00:17:16 82.118.23.15Not listedAS204957 GREENFLOID-AS- PLno
2020-04-02 16:59:04 91.215.169.52Not listedAS49693 BEST-HOSTER- RUno
2020-04-02 16:59:04 95.142.39.15vm559882.eurodir.ruNot listedAS210079 EUROBYTE- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-04 04:02:27http://office-updates-indexes.com/cloud.binOffline JayTHL
2020-04-04 04:02:25http://office-updates-indexes.com/track.jpgOffline JayTHL
2020-04-04 04:02:17http://office-updates-indexes.com/vibe.binOffline JayTHL
2020-04-04 04:02:14http://office-updates-indexes.com/vibe.exeOfflineGuLoader ext JayTHL
2020-04-02 16:59:11http://office-updates-indexes.com/max.binOffline JayTHL
2020-04-02 16:59:07http://office-updates-indexes.com/Report.rtfOffline JayTHL
2020-04-02 16:59:04http://office-updates-indexes.com/File.vbsOffline JayTHL

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-04 04:02:27141e09e70efd3a7e0be2f77530cf989b11bdbd9e18c6d6b17120e73ee21b82a2unknown  
2020-04-04 04:02:254e67f8c2e2f8aaac61c324f853db03d73adacad0bc7bbeceb70b325dcaf7b40dtxt  
2020-04-04 04:02:1740f3be4846418b992aea796170e2bbe561f49271f4b84f47879ffbbbfd00afefunknown  
2020-04-04 04:02:140e72431bb3f2c1d3fe29a14c82437c83ffbadcef763467e89137a3fac2a736b7exeGuLoader
2020-04-02 16:59:1137f0846404ec9156d93c1eb3870d9055174112454b79fae7f5f877ce57cacbf2unknown