URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: thesafezone.co.in
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 12:17:07 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-13 05:38:04 84.32.84.32Not listedAS47583 AS-HOSTINGER- LTno
2021-04-27 11:44:23 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-01-13 19:13:40 104.21.25.19Not listedAS13335 CLOUDFLARENETn/ano
2020-10-21 12:17:10 172.67.222.4Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-29 06:45:07https://thesafezone.co.in/wp-admin/ILEB2awExpTt...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-10-26 21:42:04https://thesafezone.co.in/wp-admin/OVLVNfMt3UTO...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-10-21 12:17:10https://thesafezone.co.in/wp-admin/payment/YQx/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-29 08:56:30c914f79bcecd36e66a0afaafa94fea889077dc0eeba31cb470833af137c79564docHeodo
2020-10-29 08:29:546e9c088cbe83fb2b0f6c959df9f72eb6faa3316c7eaf8e1690f590a91e56974fdocHeodo
2020-10-29 07:54:205d0b92f454b00f1679bc6b090749bf784d1fa854eac55bf453eec083b6aa2076docHeodo
2020-10-29 07:18:427161db36ab8dfa34e4ae1aefa3d4fd7923a2a89118835e1e8bc905216bbf70e8docHeodo
2020-10-29 07:01:084bfdf04e63422e1f2b89b19ccdd74439826ca27342cac0f98e259109043cb251docHeodo
2020-10-29 06:45:07d1235f6f23271030ac07ac42abbe55dc13515c9fb8586418eb81a72055ffb2bedocHeodo
2020-10-27 02:03:55b9efcf9bbdfee20efe56047ca5810ea88974d9e7b9ec968a57f814842c7946ecdocHeodo
2020-10-27 01:51:11bef2cf86acbba45a17385614351f915491d344ba1d20e5936379853d0eb2b0a7docHeodo
2020-10-27 01:21:34e955daa4404b745ed6c72a2e99899af5ad6b133c5b24f5665d4649cdcff05fe2docHeodo
2020-10-27 01:06:44284ca49487afcbd5dc06144fd8a4b4ebaf8abc174a9c0c609a5073f4925ec19edocHeodo
2020-10-27 00:51:589a5ff2d10eb6a49a82083f2f52e3daba519399794197d526ab76a68dd6849e69docHeodo
2020-10-27 00:47:40f5831fd5a2bd8c3eaf0bbd799764d684f1c3a2528d5583013b438e6f2b4f4843docHeodo
2020-10-27 00:27:58ada5eecfbbe470ecc1b1c434323530f141ac930ee6febd5c6e578dda073ccbecdocHeodo
2020-10-27 00:08:56ed7748045b321a2e819fdb922995edf21e8b02996994aaebf64df519509d669edocHeodo
2020-10-26 23:43:24ac739c4d98aa46329d4ebe114bad66247375ddaf8d148446712f2a2b8006f300docHeodo
2020-10-26 23:04:55abfcd6342895929d5baf093e13140d0b37f8e97da0253480aa94ba5e78bcd1e1docHeodo
2020-10-26 22:49:32c8ec858c06478f6261eadea96e71a453f5176eb9b07c801ad5d84bde75ccda10doc Heodo
2020-10-26 22:37:271876ecab19ee6802dac2e8774dfd625dcb2d4e00fb61f446caeabd26db1405a4docHeodo
2020-10-26 22:18:19c989f9fa249c44f5aa5e7beb1781d22d20154daae1750c5f321e00f739a742a9doc Heodo
2020-10-26 22:03:157e2498c2125b196f853bab661649d81424c604a5506801229b8b4128d3cf5a4bdocHeodo
2020-10-26 21:42:0486b0701737b73d1713cc04f83dd9e1d5d8dcee914c007cca4d5a6a1870f7b067docHeodo
2020-10-21 13:09:2790828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fdocHeodo
2020-10-21 12:36:12d9c9cdb661798fec5696237b21371f7bd3b1fdac360a68aa3fc3d863e1d6173adoc Heodo
2020-10-21 12:17:10e99ab9a43fda936582d3e49abcd562f045f62340fba2162f933fd97006ee5e17doc Heodo