URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: tbgmud.net
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-18 20:09:03 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-19 22:52:06 37.59.41.114condor.rorscha.chNot listedAS16276 OVH- FRyes
2020-08-18 20:09:04 176.9.151.147zeus.cybercitizen.netNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-18 20:09:04http://tbgmud.net/paul/closed_412212_OOB4oW/gua...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-19 06:58:1809d725bc4314f587c3132842fc1d924a1ec4952620d18e32796d3797b90e66b0docHeodo
2020-08-19 06:44:05305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6docHeodo
2020-08-19 06:16:38a0096856f8887d5cdf7d5f2e6805694ac96da153aaaa326ef25ee058e6c6a683docHeodo
2020-08-19 05:57:49f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452docHeodo
2020-08-19 05:42:45e951848d42ae155a4f81c8c0ecd4f3164426f99a023d9c9bf841f130998a4668docHeodo
2020-08-19 05:21:40948a3065cb08ddc97ef33cce132fadb8de68441de9d0fb9cc30fad5fd39be2ccdocHeodo
2020-08-19 05:05:3860529051426888b950c39051f1ae3ffd04df199460f8f08ad2fb4ae0d65837f6docHeodo
2020-08-19 04:48:475194005835c1f487f14f03ea67a9300ad9821c5d0922e5549321d2629448f630docHeodo
2020-08-19 03:17:435a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367docHeodo
2020-08-19 02:59:47682cb4ff880f1a6a000f5a227f8dba42abd73d836308162dc519644d9dae94efdocHeodo
2020-08-19 02:45:0640ba73d22e9dab3b78ab066b7fce42d3bc541832c4d6a8ce3c564f2290c0b308docHeodo
2020-08-19 01:32:50859010e3760b56ccc5e32be50378cd07f2f34509d92b112b4ec0e6e5802fda42docHeodo
2020-08-19 01:21:1663c85fe46afbae39a953f205b3b3d63109f1f4e6aabe61d3d1b9deb3ac66d335docHeodo
2020-08-19 00:57:59b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027docHeodo
2020-08-18 23:26:46eba02aeb5ab35694f34f8048ad03accea87abc6915db54d0905d905a155901ffdocHeodo
2020-08-18 23:15:4885d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11edocHeodo
2020-08-18 21:42:54f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cdocHeodo
2020-08-18 21:28:3991abaab1b3daa4a4dfe3d6c8adf5c5c8f0ec0551c271417fffd61444cbf47346docHeodo
2020-08-18 21:14:1168184e955d9a5e852a40b7c215d5654f9172d35c4e7a50e24b0080bb14c6ce0adocHeodo
2020-08-18 20:09:0455183240d4344ec16d2bf19836addfaafebea308d9349ef0df5d92aa7840a916docHeodo