URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: therapy.uvision.io
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-29 15:08:11 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-29 15:08:13 132.148.220.7474.220.148.132.host.secureserver.netNot listedAS398101 GO-DADDY-COM-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-29 15:08:13https://therapy.uvision.io/wp-admin/esp/zsO2lMh...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-01 11:09:58da961f67e8a061149fff2af056060324ca08a2cb272708f64aa3f6c71244e23cdocHeodo
2020-10-01 07:48:5787a8e577e3882ff6d9125cec05d9ca6ce949208d0866fbcb64632be14f12177edocHeodo
2020-10-01 06:00:1646a59f3fe0efcffcdfcd2c366c3cda5205ab4f7c79e6c11c1bac4ea7247906d5docHeodo
2020-10-01 05:44:47faf99c6bf7ae27773ade2ab13a7bc8ad7174d988e1e844da340884c01d1cfcebdocHeodo
2020-10-01 05:23:46d09def23b85e52761ab948f8a0a73e9d2f43f1a06c27f35973dcedbc87954564docHeodo
2020-10-01 05:02:13777127cbba49b66a0abc912156156af484a0903a78b298981ed5e34b107cc08cdocHeodo
2020-10-01 04:28:08b2af72414cca6a559fbc5e9254b6080ce9d292ef4b2a37d8973118f7fffca277docHeodo
2020-09-29 20:44:2652e0a733f1c1b48a6085aad06982e5417e6aa56dcf7d189d90cffbdad681625bdoc Heodo
2020-09-29 20:18:0520c05076ffa992b9810f1c1900121cafbbf5ca6af25b130c2c86ca2ffbdcf47edocHeodo
2020-09-29 20:01:0959db370e5d8a40c599cf93b60ad3385c1dcf1f4bf9236334c3f4b5be21faa05adocHeodo
2020-09-29 19:44:53d43559c27961577b292cd3c8f65aba9e464eea39d831d95cd2155c885c74d96fdoc Heodo
2020-09-29 19:36:1479284afdb275fc77c0504fb1f59741b1ef73baf113c4f4d4e87e66466ef143c1docHeodo
2020-09-29 19:10:2174defd8809c3c66152c56c0f711d60e7110683784e42df2d80dcf3e30c412f6adocHeodo
2020-09-29 18:48:2832049385466cefdb6902bff7a1c1c93274f20eb51842f1dc68a84e5de14716d1docHeodo
2020-09-29 18:38:522f308a1347238d06ba6169125d4ca68c95bf091d30be8381e641936523c1b7cedocHeodo
2020-09-29 18:16:0973610175404eca0912ed14988bc2019dcbdc0623dc7f780808798b0cde39bb87docHeodo
2020-09-29 17:51:12054954c8adf177996d7b60d1f0f7490910c3d38ccfa915725432a3702b1fa6c7docHeodo
2020-09-29 17:31:22afe621cd44cd689287ad44e9d1728558887078487d74729709bf5e332f7f99d2docHeodo
2020-09-29 17:10:25db692ab9e319f90b55008675167363e8045584e0bc1902963a1a81d850d4c287docHeodo
2020-09-29 16:35:49ebe5c60d0f35c3d6f839899e01aef73d251b2ba41e0d7ca848d1302b1c9906ecdocHeodo
2020-09-29 16:22:5123b449fb112ad9151ab2a3e4951ca38ed7ee57f9025e3c70de11fcdf956ffb98docHeodo
2020-09-29 16:04:3757229d906148c6f3778a3c63cca56a2130ae7815b9d77c017d06140bcc7ccc7edoc Heodo
2020-09-29 15:40:54253cd8373b9fef7b344b345f38bd10c5c6cfa760b422b98092f01d3925a51b47docHeodo
2020-09-29 15:08:12af7c73e34b40cd0fb54d465470a93b8970b711a2793f3341f48aaf5e3abb8611docHeodo