URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pfatrivandrum.org
Abuse complaint sent?: Yes (2025-04-08 06:10:02 UTC to ops{at}pir[dot]org)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Blocked
Firstseen:2025-04-08 06:06:02 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-08 06:06:05 50.6.194.24250-6-194-242.unifiedlayer.comNot listedAS19871 NETWORK-SOLUTIONS-HOSTING- USyes
2025-06-16 01:18:15 91.195.240.94Not listedAS47846 SEDO-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-08 09:20:08https://pfatrivandrum.org/images/aCfKgtyuWBBPfe...Offlineencrypted GuLoader ext opendir abuse_ch
2025-04-08 09:19:05https://pfatrivandrum.org/images/Midafternoon.snpOfflineGuLoader ext opendir abuse_ch
2025-04-08 06:06:06https://pfatrivandrum.org/fonts/HjDAVIyk236.binOfflineencrypted GuLoader ext xworm abuse_ch
2025-04-08 06:06:05https://pfatrivandrum.org/fonts/Tuberculinizing...Offlineascii GuLoader ext xworm abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-08 10:02:149387e139fc587d7b13051e9f7fcc9aa2a4f2437c6b908fc8340b3d92f6d524catxt  
2025-04-08 09:20:08d8ca5c1eff960d79da2d3819491647d52dabcf4901584aae843af9dc96cb076cunknown  
2025-04-08 06:06:058f65121296f40d03f96fb641f200bb1e060ee86742fbcc6eb6dad0b5cdb5166ftxt  
2025-04-08 06:06:056f495ad077df26380a700d50ae98add2ab05e48342f89637e7a01f7ba3bf497aunknown