URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rebeltraiteur.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-10 11:43:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-10 11:43:11 45.56.220.62v1118229.hostpapavps.netNot listedAS40092 ONIAAS- CAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-12 17:59:29http://rebeltraiteur.com/cgi-bin/ww/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-08-10 11:43:11http://rebeltraiteur.com/kqcij/x0uw_3_sd58cj6xl/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-12 18:59:19bbf084bcd83d08a6693798f851e3af34cc7c303afb235c8c25fe237ec00315cbdocHeodo
2020-08-12 18:35:48773bbccfa255f100e61a8949ed19308ff66fc817fcc06e34e5d1aa2d8746ca7adocHeodo
2020-08-12 18:14:133ac3af554f63c5c308ab18407e4d3aa155f7a2ada7a3be3b6bda7eb71fde450cdocHeodo
2020-08-12 17:59:2885ffd484ff4118230d529f8a3de7001cd925e004c7db29739a2364c8bdce18abdocHeodo
2020-08-10 16:03:531514abd490acfa6999cab5b5bc8e8b7e57b66822a57cfcea6b904d7e23df2887exe Heodo
2020-08-10 15:48:49a94de3f00cb2986c0e2508801bd15b81aba044a48409135386ac9e806d52ecbfexe Heodo
2020-08-10 15:35:026ae06ef656afcb0815b199250fabc4847eb2884db404e97d1b01ea4f3be2a786exe Heodo
2020-08-10 15:13:0734fd68e408c0d9e9b6f0ef6be583bddfd5a18e1d1937518052c12f00ede2c9caexe Heodo
2020-08-10 14:53:10a5da5e3b443b8057a144cda42275d312d534031c93380d9977911058b997b5efexe Heodo
2020-08-10 14:33:29e03d75cab97709206f2795695e7b455a8b40c8e6be6d0990e16f5cc63ca7253dexe Heodo
2020-08-10 14:05:32695b596688ec46e9f301b4212991ac079f690aa54fdf9a2a5c3f92988dba0964exe Heodo
2020-08-10 13:47:4164949f8022988d83673c0c4f05925503da2231f1bc9ddaf7061b87fdc960c659exe Heodo
2020-08-10 13:19:251eef1c39b0634ab28f2cde9b962cd28f0b6f97c58193143fe79108c1905c01bdexe Heodo
2020-08-10 12:56:568940a9596563083b6950bf7f23d378bf0f031a0328a23921dbc851f810111411exe Heodo
2020-08-10 12:37:1477bca351e50e2cc093df2cb7b876ef3b543e0bd1243e322f267d748f82a199bdexe Heodo
2020-08-10 12:21:0185a265513c0b816bc50506973d0d7c2bab13a457889f7064429c12611dc440cfexe Heodo
2020-08-10 11:43:0948fc6fd5cc496eb6b7184cf965c7f93f13bb484a912d701a7a8ffcc12cb7fff9exe