URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pangzl.cn
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-22 12:11:02 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-05-04 20:31:52 104.21.74.29Not listedAS13335 CLOUDFLARENETn/ano
2021-05-04 20:31:51 172.67.153.115Not listedAS13335 CLOUDFLARENETn/ano
2021-04-15 13:59:26 8.210.199.192Not listedAS45102 ALIBABA-CN-NET- HKno
2021-02-03 06:31:01 220.181.38.148Not listedAS23724 CHINANET-IDC-BJ-AP- CNno
2021-02-03 06:31:07 39.156.69.79Not listedAS9808 CHINAMOBILE-CN- CNno
2020-10-22 12:11:06 8.210.136.187Not listedAS45102 ALIBABA-CN-NET- HKno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-22 12:11:06https://pangzl.cn/seal-team/89107705/CvXtU/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-22 23:15:5559235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5docHeodo
2020-10-22 22:33:567e0233149682bb9be3e19f93517b3bbe9f5db41ce48dfa6ee88253a0a98bd678doc Heodo
2020-10-22 22:16:30de172d512ec3cc9e02fe2834be3639ea0cfdc900b82d65acb581575290fc2d70doc Heodo
2020-10-22 21:38:38f95869656ea95b50cdc0dcdc93991a0bff0a1c265541f45bf204766fb5870736doc Heodo
2020-10-22 20:44:158ee4f19de24163c27f25fdcc15c7a6f33424aa314467bf393e23f9ee2a59e2fcdoc Heodo
2020-10-22 20:23:27ee5fa6da862f50e1ac9babeca493ba621ca3bc57ab73fb88480bc716457e36f0doc Heodo
2020-10-22 19:56:04979b25c44d1216c7920082e1698cb3facd715ecd0d2f4f5e72c7603765b44688doc Heodo
2020-10-22 19:30:126d023a0790cfa813258bb0b0457a718d4d55c93a65b0988444b19c6279f5c42edoc Heodo
2020-10-22 19:27:17f3164116b10a1f31343bf4f0c47e83711070cf2d2fa4558bc6b869a82bf26fcddoc Heodo
2020-10-22 19:11:34171b68003d3217f50e0238721e0957d775d8eb225067a0191f56f2a31b998629doc Heodo
2020-10-22 18:43:19789b91aa9915333fc8a86c33524bd2e469d7cefca47127b96ea032ee5182bc9bdoc Heodo
2020-10-22 18:34:092459b9b17512384884b1ce25972cc817c8e218cb87265480ce229d0470ade006doc Heodo
2020-10-22 18:11:1114a549a41295bc3e3af038d8f83d8a36aea9e70fc7daeb206d189d3bfff44dbcdoc Heodo
2020-10-22 17:27:4001b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5doc Heodo
2020-10-22 17:05:58d824b5e0284791def5164b247df302a6cd675374f606a82564092fab93e442d4doc Heodo
2020-10-22 16:45:22bfc258207c269b90840c0f912c129f0f366345cdc1c88c174f59a2848a979d8edoc Heodo
2020-10-22 16:23:378c15a10ed4c619cdc9eefbb7d32596330ccb2dbc41b5e21841dd141fee55a85bdoc Heodo
2020-10-22 15:55:1465fab287607d55bb546b639bcce9b869bae1c1fda07a15c68e1b9ebe8a626a68doc Heodo
2020-10-22 15:11:4264ee7027b8c1fc6f5a53589c1b063a42cf59f5a99924588ae219a9950fbe7130doc Heodo
2020-10-22 14:59:1948c4356a3629c972a22b83fe612ed12ed47467fd7085e18ac16786cbd9c2bc4adoc Heodo
2020-10-22 14:22:124a44eb422716acd382deed2b165d37ce8de2d799d1c466a1aa2e1952f4b943eedoc Heodo
2020-10-22 13:59:345fb5309b154278b57d6a94d784dd5de602c441608e00557aa6c53c200ccbb3b1doc Heodo
2020-10-22 13:45:45a0758a339c261e0a3815c6cb511d43f7a0f86a9a0bec12a7518502d369913ba0doc Heodo
2020-10-22 13:23:09cfca456cd0b2f420fe799623f9e2bbf831e6463a73b754f9efd9f2eac8f9714cdoc Heodo
2020-10-22 12:40:242964a315de69bb8d274293c5de39c877468fa8f5395e04639fb3029533bc4c45doc Heodo
2020-10-22 12:11:06caa64b3ac297b61892889a9f4a29cb2bd5719a809c2b610c07fdd30c5c9f7129doc Heodo