URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: roobazar.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-22 20:12:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-02-18 20:47:14 185.141.104.32autumn.singleweb.orgNot listedAS48715 SEFROYEKPARDAZENG-AS- IRno
2020-10-22 20:13:04 5.63.11.242autumn.singleweb.orgNot listedAS57497 FarasoSamanehPasargad- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-28 17:47:04http://roobazar.ir/wp-admin/IdWop1jP9RgxdJULzaF...Offlinedoc emotet ext epoch2 Cryptolaemus1
2020-10-28 01:34:09https://roobazar.ir/wp-admin/IdWop1jP9RgxdJULza...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-10-22 20:13:04https://roobazar.ir/wp-admin/invoice/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-28 08:11:064a40f7f94b6987d15605eb7e6ccd22baede35a72d60278537f9aedbd6d7a909fdocHeodo
2020-10-28 08:01:10af7a1932766cf0a2a6bc07298751e49a47f81b2b7f255579bcc6d1a93f335af4docHeodo
2020-10-28 07:31:224da551741b2fdd1985b8f8dd865cbc2ee100a8d82d80a39e33f56dbda25b4f1edocHeodo
2020-10-28 07:21:1586cdca7c9ac7ecd5defa0fb8c374cd773aad5df00d6678e7f5addc0268a097e3docHeodo
2020-10-28 07:14:47089982175b8c27323227a0cbe60942992e1cd89852436e481f6947e75cb25d67docHeodo
2020-10-28 07:01:2568cb170125b6d8fe85e4573f3324f27ca595e8a2a2f0d624742c817590b42765docHeodo
2020-10-28 06:40:02087c51a90ce1975819e515fd65ce7583219cb9a7eecfe2c20191cf2d1196eac9docHeodo
2020-10-28 06:02:14f605f4309f21e3797ba0f7b9440dbd45fb913a363be8a0e774040e92e05418fddocHeodo
2020-10-28 05:47:339c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3docHeodo
2020-10-28 05:34:36c81da9358cac9552a6d4005fa1c6ed570a70d9aaca86836e670acafe475cf882docHeodo
2020-10-28 05:11:080250f0fd12c78f615ebd384a8bda63e6ff45039b0005ab5211ae72a4ab4b97d1docHeodo
2020-10-28 04:43:56f43cc95ed3a2f8900938c6a240d69a2de909494821ee8308e740e2cda2fd31d7docHeodo
2020-10-28 04:24:003120df1e06f01820a9e9aaf64e33f5ff4b4e39647ef7552f6f98535a9c17e68ddocHeodo
2020-10-28 04:09:33d3e4041b0325e0794fe6a1b0a78783b8c05b595f0631c24d7d8e11c53fa5e8e4docHeodo
2020-10-28 03:41:49f3caca68ae462481d5bac777996fa838a0dce95c7eb782713404fa5e3712a2abdocHeodo
2020-10-28 03:20:52c3e8b7bf6e9c96cf2335ab8c491d537cf81a2c322e9b305fd0545d051c613a83docHeodo
2020-10-28 03:00:22cf6945d684eb6962274cca88159c3f88a0a5291a81ac0d8831d9f6496b005c33docHeodo
2020-10-28 02:37:39384f0ac6af41ed895424d29854b510286d7b1c075150dbd313f8682f26eb4249docHeodo
2020-10-28 02:22:4143159cae0059060554e0c283a577d48c0b825e44856b3afcf24ac2f6ef831334docHeodo
2020-10-28 01:57:275e692d0f6341638d540a0dd0458062a4852cdc65dd6551956aaa28c4d417416adocHeodo
2020-10-28 01:34:0942437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17docHeodo
2020-10-22 21:36:22838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fddocHeodo
2020-10-22 20:44:44afd227b07c577d52646f947182d3f65be45a70cb65bbc5316ecfae58e51e33bddocHeodo
2020-10-22 20:32:19238792d4ba0b88404023737e62f4d3768816f979249a65ede0d4ef2cd227f9badocHeodo
2020-10-22 20:13:04143a635255333363ae3017af09505f23784d4fe518164c2c25d97f8b8ec77e4adocHeodo