URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ph.sci.lru.ac.th
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-11 21:53:07 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 12:26:01 202.29.6.43Not listedAS131246 LRU-AS-AP- THyes
2020-08-11 21:53:09 202.29.6.21Not listedAS131246 LRU-AS-AP- THno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-11 21:53:09http://ph.sci.lru.ac.th/th/hpx842j8b/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-12 09:05:40408bd6525ea4e38ffe39a42a4c24c314099dff289a0cf7ff621c7f171c63792adocHeodo
2020-08-12 08:30:39b00309dc3091f93c13fa36bd5d5fb4f1d080f70ab1eabe94d84eb8423dc3d5dbdocHeodo
2020-08-12 08:13:0081c27d10e37bd700d8cee11eba8d01d2bda91b7743083fa7a4e51f3f169ef0c5docHeodo
2020-08-12 07:55:22214f91b9b3ab2ea28b14536241901516f9141df4e12fd3b2ce52088fef0a3734docHeodo
2020-08-12 07:29:46fe14ae5d76ac1ccafc67f474efe315000dadae344444a44c9200e04e94ebbdaddocHeodo
2020-08-12 06:45:03025046a10693eb1c9dca8e64fa2dc55f1ba16ff9c6650493205e2c3af827e1dcdocHeodo
2020-08-12 05:58:409492fa4f34cceef83ff1e6f77bc428777aba7ae617b195a3e6a06d84e5889b1edocHeodo
2020-08-12 05:42:43c978e204a4343d19a9b1df57379618a391455fe0f0fd17e49fcb670670c4241cdocHeodo
2020-08-12 05:25:486f973501cc2dece992aa2f959f8e352e424e96f06abb300b4bed8bcf2ab4bf34docHeodo
2020-08-12 05:10:111d2096f4adcba717670858b98912615f7bc86bd95ef6b3117901aa4ae6383d4ddocHeodo
2020-08-12 04:49:45f9f228e552c3971983d4b5909776c052df083b9b41f65f764ceba0dc9d6219e7docHeodo
2020-08-12 04:32:03e95c19b3173d0c69d60efb950859b2ffd3020235efd6c47ffebddf950a0edf52docHeodo
2020-08-12 04:16:3229a8f854081e5f20b6709851863472cd33a1863fbed4867153edf6fcc5e86dc8docHeodo
2020-08-12 02:53:427f3f157b6efccbe88e544e49aa6b5571503e8f8e2d187cb88f30a38860b1537bdocHeodo
2020-08-12 02:29:414bf9697c195958d66c73bb025fa342729e0204178694ba1e36bb6760c7d02ca0docHeodo
2020-08-12 00:58:23358176ae69d49cbdc29ce5f8965efe9952253949970d9de4e8f09f46c488e6ecdocHeodo
2020-08-12 00:43:275d38e73c8e461773d7bd09fd69760d3e0335e51cd3df39676a4c2af22343c43cdocHeodo
2020-08-12 00:27:33e4d1deaefa7f905c5ce7490867ae09ff2d50fdf4162f102e276653c1c46eeab6docHeodo
2020-08-11 23:43:135a95e436c4df9dfb41496c96489d1bddf6db2c7d54ccf0761eb61ef1af9c83a0docHeodo
2020-08-11 23:00:33896db11ae3dd47bbbdaef6de2e44964142461c89f1fd377015b96affcc75cf60docHeodo
2020-08-11 22:46:54854be831ad01f15c5a5cc2f0f253d059b2a9faaac66db5b90fe51b3daa401c57docHeodo
2020-08-11 22:32:131aac25866333e7f77dc237137353a0a65ce189972d87658229eae96e3037bc68docHeodo
2020-08-11 22:17:481d09b28a4d454266d52d7d2e5b9aeab2bbf43839ec33c9a7221eafae3c28c067docHeodo
2020-08-11 22:02:096c5380e193b725ec3ea512a3146d8c0925c7c489800dad57d1b4b2f940751d22docHeodo
2020-08-11 21:53:09ddcfa6beac3f79149c8786ca9af44062331f6222f46f5ccfb1429ff859308dacdocHeodo