URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: safesalesnembutal.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-05-02 13:32:02 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-05-29 21:01:45 209.99.40.223209-99-40-223.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno
2019-05-29 21:47:18 209.99.40.222209-99-40-222.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno
2019-05-02 13:32:04 184.154.153.1818.153.154.184.unassigned.ord.singlehop.netNot listedAS32475 SINGLEHOP-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-05-02 13:32:04http://safesalesnembutal.com/dgbx/paclm/vxa4bpq...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-05-03 01:42:43990801c1de058647b506c19565ee7abf0c886af33defe87c185c91aa65f9b579doc Heodo
2019-05-03 00:56:328217083c9e4b5ff7f2e438a2e50d8fbc5f75cd170801dcbd6bf1592b4ee6e76edoc Heodo
2019-05-03 00:18:31f268669cf7822cdb42f9407a39e23549e79930c64deabf9fb45acb7c33aca728doc Heodo
2019-05-02 23:48:34f38d5609ce63487e3e63cdd748f198d3e2afff98ee43ed99880ccac6a883d3b6doc Heodo
2019-05-02 23:02:30e94720b4121c2f2d41e0ee3d754100229d76b7f7085c5700cc059ac806f0a59edocHeodo
2019-05-02 22:15:27e3a103a9172dd50524b0c0964de06d03923e3570e35af57064955fbf000d459bdoc  
2019-05-02 21:38:244a4e5f7221b64a94e9ef4e6aa74464802d5156b0fed3258d36bc778233fbf8aadoc  
2019-05-02 20:54:230971308893645e1e89941d0f1534015f97e2cb928d9109721c7cd7cd0ea1cac1doc  
2019-05-02 20:07:20abc589d5ec63138ee0c588f744cb6c8ba59baed47e9316419c174ef6e6a7e393doc Heodo
2019-05-02 18:33:2248735c4ff3f7651891f927ad38236a63867ffcbd2a702e9a79daa03cd9c63420doc  
2019-05-02 17:46:155a065c412c5ca5029a12a0c5bb8fc9ea3fbe72f7b3a89fa7fbaede2f06ae8185doc  
2019-05-02 17:16:120aba359f77ac576510a26b160b60e4b0bc470db5ec0341e64234681ec8c607c1doc  
2019-05-02 16:45:1411f45c2f0d6d243306cbd6c70c01f1efb2050836b14f4d669b7a471511ade739doc Heodo
2019-05-02 15:12:1761363331b4ed5c211a5108f4820e0e7b31451bb9fb50da87d537b88e01159528doc Heodo
2019-05-02 14:36:125df383f04feac1ecc7ff1cda2e577d97e612db6ded6d2d33830eaaa3fc0d569edoc  
2019-05-02 13:56:12456c3edf43e0677174dad7da916faec9c2534520655a62ad5be950b123060daedoc  
2019-05-02 13:32:04fa0e3b3660ec8e52b4817f8e030a678bdc2308af9c111f8241901d1e0a7396dbdoc