URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: schoolclue.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-10-11 18:41:22 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-04 03:09:35 185.53.179.128Not listedAS61969 TEAMINTERNET-AS- DEyes
2025-10-13 18:39:27 199.59.243.228Not listedAS16509 AMAZON-02- USno
2019-10-11 18:41:51 198.38.82.163mocha3021-web1.my-hosting-panel.comNot listedAS51713 WHG-LON- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-10-11 18:41:51https://schoolclue.com/66eo/yhfmv4582/Offlineemotet ext epoch1 exe heodo ext p5yb34m

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-10-11 22:02:479226a5552470fc7a251c1aaf5ca873e15c787cd9f7266e3d3977c8028e4036ceexe Heodo
2019-10-11 20:29:18d7e48995f37ac2d3de583b3b9483d8f9a73180b01209a75b61f3b76777144bd5exe Heodo
2019-10-11 20:00:1155f6602485f9a39f2bed688073d5419ce691ec0c1b827a06c7213dc92f619507exe Heodo
2019-10-11 18:41:51946c4039f7a95d96da815c4bffdb13c564bf7c6f8959de7357f181e77337d6d9exe Heodo