URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: spread.ooo
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-03-07 17:34:04 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 19:12:06 192.124.249.32cloudproxy10032.sucuri.netNot listedAS30148 SUCURI-SEC- USyes
2019-03-07 17:34:05 111.118.215.27bh-in-12.webhostbox.netNot listedAS394695 PUBLIC-DOMAIN-REGISTRY- INno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-06 11:55:28http://spread.ooo/mudcafe/report/Offlinedoc emotet ext epoch2 heodo ext spamhaus
2020-01-16 22:45:06http://spread.ooo/mudcafe/Wia/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2019-03-07 17:34:05http://spread.ooo/mudcafe/tfmj0-fntvlp-dysv.view/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-06 21:30:002632f54ff03da6748cd94b4dfa7c750dcf28976dc3c60983e594c50cfd49496fdoc Heodo
2020-08-06 19:58:056404a5a49751db7e1c82b5bdffadd5171eea2b5a4b43f9b77afb50b2095df09ddoc Heodo
2020-08-06 19:40:5193c870008317b819f86d45c0c3e0075eae202d632a8c5a15afafda0e60ba9551doc Heodo
2020-08-06 19:25:33ef6c1ffd05150882bfc54a821a952bd6f743e63a03c52ed1564f9ca8549299cedoc Heodo
2020-08-06 19:09:23c587f3652820270bba59542522120672e8e95522ddcf9ef94ada4b00271b3bd7doc Heodo
2020-08-06 18:52:043d7b0b0b8db48edd63f38207860a39c39f05ca912545fae115149ce35b949740doc Heodo
2020-08-06 18:41:185475cfc64e19f8a7195be93c65b59fb767c78681a8776edaf2914d43242326cedoc Heodo
2020-08-06 18:33:5849293332112aac8e7324c776e9ea01df8d9c3029f9d89b1883863fa4ac4335ccdoc Heodo
2020-08-06 18:15:59eadc186cfe8e3c19ea300adfa281efef73f5792352852efab0420e0389b49bb5doc Heodo
2020-08-06 17:58:47b27f4ef8f5469f85fe50a642dcc5fee52880b25c23819000768cbd8055093726doc Heodo
2020-08-06 17:42:27bb602d79341451698628307e329d7effecfc741d8cce9a03023082cca9e7fd6bdoc Heodo
2020-08-06 17:24:4690349a6fef59a2961f650f14597c52d61bcc6b18d8017591106c662239d21a8edoc Heodo
2020-08-06 17:05:318dfc9301200294d18edadcff9e243522a1a82a3378e5a874e18dd11a47204a34docHeodo
2020-08-06 16:44:5498826e022ea7e43c4ca336a98b7dfb45866836324f79e8e7af3eb4af39686c22doc Heodo
2020-08-06 16:22:27c7600a3fc42b6fed1538b5fe0a9d93a62b124e58f5c96b976422f1670cab0016doc Heodo
2020-08-06 15:58:03082b3011f9082a24a8638f4c1e707ff092cc1461362041ae4e3e621be475b1b5doc Heodo
2020-08-06 15:39:07dcf13e777cc81ba6dbf2ebaf5747e5de599a4de2aefffe544b7f52c9e0188827doc Heodo
2020-08-06 15:05:20b554adbe36cba4bab4728dd27cbe944e169443554e2a0cb67e1410fefac08049doc Heodo
2020-08-06 14:44:103aea71cb3bbb127254bc652cdf318ad814683e16c4c9f8fb7c6e84d42d32553cdoc Heodo
2020-08-06 13:13:55fa7a2f035cfa8ad6cee98c7429474f64f136f99a81f8f1047463efbedd4e7094doc Heodo
2020-08-06 11:55:287d36e7bf1b5cdcbb921805adb5c1d2ad2b9409ba4ce71767d57768a395300e11doc Heodo