URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: palafex.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-28 07:40:04 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-15 12:54:31 104.21.89.63Not listedAS13335 CLOUDFLARENETn/ano
2020-10-25 20:31:30 172.67.156.226Not listedAS13335 CLOUDFLARENETn/ano
2020-10-25 12:27:44 130.185.122.211Not listedAS57568 TR_Arvancloud- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-28 07:40:06https://palafex.com/wp-content/INC/qN8iZfFuw9r5...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-28 15:48:38e2dcc502dbfd89abcc734d23ad35f6b20ebf7fce35ba4cf7aecb716acd5d9c71docHeodo
2020-09-28 15:16:426475756c88e423c4da1fc069bcb97909e3c18ea68bd40164abefa00cd5aa4758docHeodo
2020-09-28 15:04:5090b5f100db7341b2495c748b065e22c02cb9851a35759168f09d015710ac2f1fdocHeodo
2020-09-28 14:41:098ed37594d6584e0799753a477d07666bf837b8b655d82f4e66efd1b236209e5fdocHeodo
2020-09-28 14:31:1105d211a76b7dfa7c4cdd3b5865e73248164464f5a97c5b3b51e0b6e06fc6fda9docHeodo
2020-09-28 14:09:171f8ec4f43a822987e0d084649f52bdcc439465804a71f47c8c6a086723feb4bbdocHeodo
2020-09-28 13:56:57c41f70d35decb29c3b6e8f406423d0747fb4bdbdd66c54a01cf86567c4ce603adocHeodo
2020-09-28 13:35:093a9ad1adfb25f584b952d1ad565b13d074f0a2b396249138449c29016187e362docHeodo
2020-09-28 12:58:472dea2c6adc30cf2bfecbc99581061f715ec35d2a52592359fabcc6373ae63d03docHeodo
2020-09-28 12:54:28b993db6027f3ab4a8a0bf84b89deebe50f9b01854a5849be661ca177a6ab6b1ddocHeodo
2020-09-28 12:40:3982da3daffe6bec3ea5b8a5e9897d4491d5546f3205b86d40781b14ae8428c642docHeodo
2020-09-28 12:33:51f82b052393cee12ae48129071061e5ec4a8847598bb634cde1930bb8e3fcb21adocHeodo
2020-09-28 12:19:0691646523a0f07719b33e85b40459fc5b5f963597e0c28b080523878c5d4f828cdocHeodo
2020-09-28 11:52:54393a299b00878cc2ee1144a56c9a9a50d7201d9e2a6d9f88a5100e0ea644ed25docHeodo
2020-09-28 11:42:218b9dc4a4d093ba6512626203861d2a2f870ea4e8c403392bff15b5994284473fdocHeodo
2020-09-28 11:26:420e0e0433ed03da08a0f5c04edc298d1fb7d169e296a5395752903154946ee846docHeodo
2020-09-28 11:05:277927857c4b1dcec9436a825b84c90105e6ac82cc863b74f8aa821e36645fbddfdocHeodo
2020-09-28 10:44:352be4930444a8fa58818baa0167214374b9bf0fe31f99d57f232bea1aa0e2daa8doc Heodo
2020-09-28 10:40:0650bef11268e4a6c5d13e83800177e1957fad3d991f8ceea729166bac747f69fadocHeodo
2020-09-28 10:26:2779a644f95bea07a6037876d6bb87d78f3b8086d125855ab70c4e8dde6943405cdocHeodo
2020-09-28 10:07:2277a5ce5a7dadc4224e8c5948cb2fbc53d3de18ce501b6e403910c8c98b0cf7fbdoc Heodo
2020-09-28 09:42:51724c3e38a059659ba8ae1956b91aa8fa3d064d3f56c9123e518ffd02b32b4758docHeodo
2020-09-28 09:33:03984e84ac950ad50b540bfd1610b17d5c9c8b78c09f0645205575be175b5757ccdocHeodo
2020-09-28 09:21:00adb275a9d586ffdce9c11b1682d836cfd913b9fb67846c7f0e300dda34c0a9e9docHeodo
2020-09-28 08:58:334569bc2e1ac13672c6927936f038ddf0e88b3de1fff148824ea53136f3aa7c8fdocHeodo
2020-09-28 08:46:1201bd1ac3283be5ae08dec7a54aa614d97721d276b8b567a98c0fde8337c7096bdocHeodo
2020-09-28 08:35:3387949cd6634619957742e08d726837cd882257e0e9073ba608adaa40c5e09851doc Heodo
2020-09-28 08:15:46060193c6b16cebe604d55e60cc04c738830a56bd46316ad3ba0f5ef26bc5b806docHeodo
2020-09-28 07:56:575f1b8f44eea91442867d766a536c262db0c65a55021ee1dc853917d32c1f1776docHeodo
2020-09-28 07:40:05513c4099afc8ef304e95c9ec465b89100f31b849d422f051a854c4a28cbde144doc Heodo