URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: okbuilding.ge
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-28 23:36:53 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-28 23:36:54 213.157.199.149cpanel10.srv.magticom.geNot listedAS16010 MagticomAS- GEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-28 23:36:54http://okbuilding.ge/cgi-bin/invoice/0166127/60...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-29 09:37:065df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4docHeodo
2020-08-29 09:16:4153a81757cc45ec010aa2b5bf957b383898ab0b91b52e51adf5a72e44a9845e51docHeodo
2020-08-29 07:44:573b5c4fffd6b0548d5d66842086b1b3762032be24a72ceb3154d72cc55cbb8d83docHeodo
2020-08-29 07:27:24bafeb0485f36e4e1ba176fcbc1b43cec6639282dbeeb7244c56f9b98fe8df5bddocHeodo
2020-08-29 07:06:56139e6af741bc7d94ee44f8a69dbc8e694a72bb780b0b984a2c57cc99966d3e5ddocHeodo
2020-08-29 05:35:4063b6721473e50f9b390f116cda2dc97aff00e66766293eae82b907ae7ce0c375docHeodo
2020-08-29 04:05:413b05f64f06873b3ad6438916c81c4f4139191b2d5a8324a632b2ef7fe4a82803docHeodo
2020-08-29 03:31:561f42096613819f1b1cf2ea163ea893ccc965e8b3fc9beb61d4b0a967d2374bb5docHeodo
2020-08-29 03:17:21b7a2a470b35a3cbf4a6501f45709fa7cc29d2a33c5cac4f00ac64b426b90929edocHeodo
2020-08-29 02:54:50b8029c0d90d1b4ff550cf1f13603ccb9b462e64c8b81afc2ac33252b86839931docHeodo
2020-08-29 02:36:583859539d7b23160befaa0ee026d5fadadd14d18b595a63a1d2adb1c103a7092bdocHeodo
2020-08-29 02:22:3660f661d0a3444cbf34c1c249572f83e9d7c73bfcf4aec6790b856574c1906aacdocHeodo
2020-08-29 02:02:35939a22a6a05d99ab11db0eb510017c9c6729c96dc78051736fd36ec777fe7196docHeodo
2020-08-29 01:49:35a936fa77ef0be55ddc1bba6a24c65da623b7207d45356219d55b2475a4234b9cdocHeodo
2020-08-29 00:20:047a2ea6bf67afad967a724ca65954848493d2b3d60c68a583219c0d8acff06db4docHeodo
2020-08-29 00:03:188c3d2e0fd7d2cc86088185bf1acaf32d2d7e43124beba918f38856179ade8097docHeodo
2020-08-28 23:49:3676b27ec8a97aaff0fcb904c903f9813d51120eab33ba6c8e2624e900e8863b94docHeodo
2020-08-28 23:36:54c8f5b268d03379e5d76ea814b115e74877113e741519f8f46585a91ab8ab70b8docHeodo