URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rockhilchurchug.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-21 09:32:02 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-08 17:13:57 63.250.38.14premium91-4.web-hosting.comNot listedAS22612 NAMECHEAP-NET- USno
2020-10-22 09:00:52 161.35.9.21www.symphonicmosaic.comNot listedAS14061 DIGITALOCEAN-ASN- USno
2020-09-21 09:32:04 142.93.161.89worker2.leadrebel.ioNot listedAS14061 DIGITALOCEAN-ASN- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-21 09:32:04https://rockhilchurchug.com/wp-content/esp/vuUt...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-21 10:30:073e852ee596953598ade5ec15aca21d6360f378edb62269d0b2d2c9ae5c8d3bc7docHeodo
2020-09-21 10:02:17d8fa1fd9d6875f094c2397135903ec7e871ca63b06a471a6052b8cda6d7b208edocHeodo
2020-09-21 09:45:16374523e9d054ba30d59eaaa8686fe97fc74a10882a0b467d52b21de5efddc31adocHeodo
2020-09-21 09:32:0414d45f947ad30ce515c35815942b9f76eb1b8feb7828112e41de5bbfe9818047docHeodo