URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: theculturetrip.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-23 02:03:03 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-29 17:55:05 104.21.18.100Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-29 17:55:05 172.67.181.145Not listedAS13335 CLOUDFLARENETn/ayes
2021-01-23 02:03:04 78.110.50.141Not listedAS12616 HOSTING-MSK- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-23 02:03:04http://theculturetrip.ru/d/wlx7lGpiGfeOk8FJOkrV...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-23 07:36:24526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7docHeodo
2021-01-23 07:27:0133c3b2856eefdb51dd0d8798ddaeac57d3a1b63fe1cf86732f08d2cc5b1b851fdocHeodo
2021-01-23 07:08:5657d7ff4664c6bffcb350211f1d9cbc272747c201c3c784fcfbab0f49c986f53edocHeodo
2021-01-23 06:52:53d748bb7a8d447b8bbcbea5a3d20a404351c3ea3dacc3f332a41f44f138be5320docHeodo
2021-01-23 06:42:36e84a53c9c72675201ca77b855375618ecae8bf0f4ce43acb1ba16b53f5a67eb3docHeodo
2021-01-23 06:31:5013b8d921ba75e923bed58dbd4f76435ad3dab789947ffe7279fcd804cba1fda0docHeodo
2021-01-23 06:18:2928b78d04a0fa5ba6b6c3504f9d9a7664f16710d02d2e92be72e97f03ae3a690ddocHeodo
2021-01-23 06:03:17343a9444d82311b35e225e7f819846eb81890d285f051585d33692e2d78fb73adocHeodo
2021-01-23 05:50:5110dc55d6131467b2ef53cc13475499dd9f34965a9c847672f707617fc6e2e6cddocHeodo
2021-01-23 05:40:10dcfb145c4f46a072e988cdeafc065f8116dc3b27d6bed447024677f3ea2f252adocHeodo
2021-01-23 05:28:29d25637cf316cb6635d17034fb9bfe5334c47f0ef16cc18b178f1a74a48c9b178docHeodo
2021-01-23 05:08:3802e4aa3af6d4d0a6c3f5965922f7ec76cc4302e17b7ca1c2f28601ab53f76be9doc Heodo
2021-01-23 05:04:2922d173bf822ad2a201b67dbe4adffb9e3542bc1e72c408fafd435b91ea6ea799docHeodo
2021-01-23 04:43:1724093743cc1b5882bb6b43c3712d06a13dad73e41f2c95f44d71286d515a1120docHeodo
2021-01-23 04:30:14a5e5efdf01f81fd9ba75a7f4a0f2ff53fc5f9f7b3edb6b80036f3add9d1b370bdocHeodo
2021-01-23 04:25:253e2601aa7c53742f621bec3989a72e0c2db710586817cfc0067b9557e7346935docHeodo
2021-01-23 04:13:50ac3a231f0035c95d710e53ec6dd86a4a915dc23b12238c4d118e7c2b656cad2fdocHeodo
2021-01-23 03:59:34422c84eb3c0a25bf5ea4c23eb23b048c1ff8f1dda0510c84362dc30ab3fab6d7docHeodo
2021-01-23 03:48:02bbefec31ea0c2301e8202d73acf49ca0d72f4a3b80b6a81836e49b1591d3d78cdocHeodo
2021-01-23 03:37:280d95efeb799d69a27255270804aa8efa5e91cd71b55943e37e88e772c961bca2docHeodo
2021-01-23 03:26:11cb4aaffb479ed567e1cca60bdb16fe0ede6ca520f16b1129e28eae589d6f37f6docHeodo
2021-01-23 03:00:42d8ce6bc970178e61cab2dc65747d72cc90c005e63a058466f561d1348a1fa140docHeodo
2021-01-23 02:55:07e621537a061ede5d0f947fecfccc7e9568fbc21942c2b64801138b227e4f23e4docHeodo
2021-01-23 02:43:43ac612e34cb415fcaf5c0ae462ed0e4efee5897879ee434b80354b39fe34e9317docHeodo
2021-01-23 02:22:303b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58docHeodo
2021-01-23 02:13:51d926e60d6b78f6b07a61842aa31c25077849e0921bbb8c454900a6b1447427c0docHeodo
2021-01-23 02:03:04d24e032bf95e95b0c1325688cb50b3eab851e90b9350f1a031668dd2bbfac3b6docHeodo