URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: siyahkalemresim.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-11 15:33:26 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-21 01:48:25 185.118.143.47spd.net.trNot listedAS57844 SPD-Net- TRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-16 01:20:10https://siyahkalemresim.com/sys-cache/gvz7xbiu8...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-10-01 01:46:15http://siyahkalemresim.com/yedek/invoice/kpz9b3...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-09-21 01:48:30http://siyahkalemresim.com/yedek/FILE/TF2FFKWA2fk/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2020-09-21 01:48:25http://siyahkalemresim.com/yedek/Document/b54jj...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-16 01:20:10dbd52eeae1181eeddab6c7e1fc6a63564fdf6c6ab43a2ce880a8f1af89531022docHeodo
2020-10-01 01:46:15a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47docHeodo
2020-09-21 01:48:30b8bd94ad1c25d6f451b5118230f8f71ef852cfe1a99f050e457b1616c039a564docHeodo
2020-09-21 01:48:25e9325a711e0f6f605b85898c5b507d4320e1f1dc672c68172b06cda359b5107edocHeodo