URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: reader.euskadigital.eus
Domain registrar:10dencehispahard -
Domain registration date:2017-03-14 11:39:13 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-18 13:51:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-01 11:16:28 79.116.152.5879-116-152-58.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2023-01-05 02:27:06 79.116.53.16179-116-53-161.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-12-23 15:23:06 79.116.52.1879-116-52-18.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-11-17 12:10:41 188.26.207.234188-26-207-234.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-10-03 15:21:17 79.116.42.13479-116-42-134.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-07-15 14:21:54 188.26.204.114188-26-204-114.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-06-23 16:42:21 79.116.53.19779-116-53-197.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-03-25 12:00:02 79.116.23.13479-116-23-134.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-03-13 19:03:51 79.116.43.779-116-43-7.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno
2022-03-11 00:56:26 79.116.13.21079-116-13-210.digimobil.esNot listedAS57269 DIGISPAINTELECOM- ESno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-18 13:51:04https://reader.euskadigital.eus/vendor/rKssCVCq...Offlineemotet ext epoch4 redir-doc Cryptolaemus1
2022-01-18 13:51:04https://reader.euskadigital.eus/vendor/rKssCVCq...Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-18 14:10:47203afcf45c6c4b26213d835ba1164816c6c5ff9617e763481ecbd90481f1c581xls Heodo
2022-01-18 13:51:04eab2257b40a134198b1dfd8384f0788ebc3122a7bb9ffee941be9d4454bf4a7ahtml  
2022-01-18 13:51:04fa10d4c1be08f4e283bdaaa42a1d800768187162e2d90bb494fa4367dcd494adxlsSilentBuilder