URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: s165469.gridserver.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-14 23:03:03 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-14 23:03:04 72.47.228.68agaacqsasc.c04.gridserver.comNot listedAS398101 GO-DADDY-COM-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-14 23:03:04http://s165469.gridserver.com/2e4e/DOC/v4Ni8lfQ...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-15 06:11:10a99e5fef8c2c166acf8dba082f4cf5354ea32e0b06c34f8934c6dd577c11e619docHeodo
2020-10-15 05:49:13cdeb15d8db3aac2e8aa7f6662d3e3e84f3a2cf8a1f4fadc399152bbe441ca7dbdocHeodo
2020-10-15 05:26:593a46985169f505f6e3794f6da48b0678d7a077f95379a6340afeab2f08914941docHeodo
2020-10-15 05:18:0172e8e736fa3a59434029878c15ccb716e521fe24b7b2ce2a0164e563953f0e1adocHeodo
2020-10-15 04:47:292c8b3647bf5e9e3bbdcc344e549271d9b94a24d5147e40774ba7e7f278753e33docHeodo
2020-10-15 04:24:57ce919ba0fe4138b6beb54fd7e80f0610ad82207bcec47cf3a8d5e1417510edffdocHeodo
2020-10-15 04:07:44dacb8606972dbc1049e006d9f6ff46c1f0fc9ca4e70dc596b282bfda43921c77docHeodo
2020-10-15 03:21:57ce123f1245402d6d932c41410dda3852ad4aa293426ada391a0517fcb34eaa12docHeodo
2020-10-15 03:04:389d44f5bc1e5b37b6a8f56a6e027e8710e8deb18e94d76d6f2ae0ff545147d53adocHeodo
2020-10-15 02:31:33ffae9f1443c5cbd247fd6ff5739831846799863ed5949cbef3bc09a0429aad5bdocHeodo
2020-10-15 02:03:499bb59da13df6375af3a01dd20c837eb0a91087a5c287daf30f761fb672dd6342docHeodo
2020-10-15 01:25:35dfa7ac2aff5f17bf9fd8f20689072101fd94201259f81e59603377107e1d8468docHeodo
2020-10-15 01:12:0873b057ae8d3a2b139db1471d05c4c3dfd956d5dfe92d1a7c651aef8a0e3b01f4docHeodo
2020-10-15 00:57:555e2776b0be25cad00ce38d390a99aa4cb5be83befb044944673f6fa495d2f854docHeodo
2020-10-15 00:25:581f95ff5c4468e0a6865433408a409b80752da669b456ea5b93e96d8c30def8dddocHeodo
2020-10-15 00:16:32b79500f8edadb8b8659659e5d968754a314bbca03bf12bd40216d4ee100dc033docHeodo
2020-10-14 23:52:5229e077bcd4cfa3620323fca9bfe5822d017cd2a8c81590b281792908a39ba343docHeodo
2020-10-14 23:40:33e53072790fadb0467c8ca0ddb901634e878eac42c5ef6e1b3d97ae4e28f42b79docHeodo
2020-10-14 23:09:10b0d0157ad106f6049b8478bd74d5363467c025cf3f7864ec21ad37c30391eef9docHeodo
2020-10-14 23:03:04a49020010a8e7d4bc405bcc23b9351dc19467c3d466e2d903c6df903668d51ccdocHeodo