URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ptc-bd.net
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-27 10:54:06 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 05:34:33 66.85.143.2rh3971x561.rivalserver.comNot listedAS20454 SSASN2- USyes
2020-08-27 10:54:08 66.165.253.23566-165-253-235.static.hvvc.usNot listedAS29802 HVC-AS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-27 10:54:08https://ptc-bd.net/wp-admin/sites/1802928339284...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-27 11:47:54262880b400d99283c606eac7c8f305097817ae5c81aca9961970efb5176cd961docHeodo
2020-08-27 11:30:139732d75740a7a624d5ee933c6cd49e15cd59c7c4f692e895dc9a219981028e27docHeodo
2020-08-27 11:12:36da824fbeb1aca76e08e78a0e568930de8ef2c71147fcdc20943bf61f59e8a477docHeodo
2020-08-27 10:54:0870bc2a3ce1968437f2a3dbb114e000c23bc3882e53d4b963cf326ff03b84487ddocHeodo