URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: skare.net
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-07-28 07:14:16 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 13:06:44 167.235.84.109cloud09.nordic.hostingNot listedAS24940 HETZNER-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-28 07:14:19http://skare.net/cgi-bin/uKq/Offlineemotet ext epoch3 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-31 23:38:15b03ff55cd67297d4bfee7d88220f770c67db4fcab2076587e2afd398353c5365exe Heodo
2020-07-28 08:07:5483267d1c1b63552a5fbd022b2b15e37c78b6cb27eb58049ddd15318c223661e6exe Heodo
2020-07-28 07:52:079fef990cf00d13fc01786ce669b61f8fe9ef11fc509fd6b551ed22953dc0ec0eexe Heodo
2020-07-28 07:36:14bf6ea9f9e809e9e218e15ba673bc2eccecedf761e0c195fc64e4b99e748eaba3exeHeodo
2020-07-28 07:14:193a6c2bd2d065d2da7ad6a2361ee59e129cc461f53360534cc234ab7214200924exeHeodo