URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pub-bfc34934a91a4893817098f73415917a.r2.dev
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-08-21 10:00:11 UTC
Total malware sites :5
Online malware sites :1 (20%)
Offline Malware sites :4 (80%)
Newest active malware site :2025-10-26 13:08:17 UTC
Oldest active malware site :2025-10-26 13:08:17 UTC (Age: 7 months, 4 days, 10 hours, 57 minutes)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-21 10:00:29 104.18.50.34Not listedAS13335 CLOUDFLARENETn/ayes
2025-08-21 10:00:29 104.18.54.45Not listedAS13335 CLOUDFLARENETn/ayes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-26 13:08:17https://pub-bfc34934a91a4893817098f73415917a.r2...OnlineDEU geofenced BlinkzSec
2025-10-26 13:08:09https://pub-bfc34934a91a4893817098f73415917a.r2...Offlinepowershell BlinkzSec
2025-10-26 13:08:08https://pub-bfc34934a91a4893817098f73415917a.r2...Offlinepowershell BlinkzSec
2025-08-21 10:01:31https://pub-bfc34934a91a4893817098f73415917a.r2...Offlineexe revoke-cert BlinkzSec
2025-08-21 10:00:29https://pub-bfc34934a91a4893817098f73415917a.r2...Offlinebase64 ps1 BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-26 18:14:0151bd2a9b2a7cb8e27d2a0011d770d65b14b51fe5d5b0f647fc39eb25945de40etxt  
2025-10-26 13:08:09ea36101d6c5102fec766a5437479a8606a6926633caeea88b55bca1e33b5d6a9txt 
2025-10-26 13:08:088469be9fa98fd562e21d9bd606ebd54b4918516bd310f0c1dbb9cd79394eef1etxt 
2025-08-21 10:01:3190d7f4352676535a9f76083ac0a63a6c0e11e08dbd1084f6ba28ec0eb69ada3eexe 
2025-08-21 10:00:29c62aeb585c293e7d8ade3cb1b6c8afe06322adc9b96001faa5e10e323125addbtxt