URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: thetastrike.forclientdemo.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-11 16:13:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-27 01:42:51 104.18.54.58Not listedAS13335 CLOUDFLARENETn/ano
2020-08-27 01:42:51 104.18.55.58Not listedAS13335 CLOUDFLARENETn/ano
2020-08-27 01:42:52 172.67.210.106Not listedAS13335 CLOUDFLARENETn/ano
2020-08-11 16:13:04 192.34.63.244Not listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-11 16:13:04https://thetastrike.forclientdemo.com/sites/ava...Offlinedoc emotet ext epoch1 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-12 00:58:58972372bf61555e5ac2960184e0c02960b7ecafaf9af5649d7ab2c7d0ef73e090docHeodo
2020-08-12 00:43:47239b0c4f5e150bac96fff321ed672e0772718018ae715db9d4feb0b59879fbb7docHeodo
2020-08-12 00:31:22d61bfdfe3cb1c215d30ba7049a17251c36f1029c9d6bca013dd3bbbbcb8d6b64docHeodo
2020-08-11 23:43:05db2aadedc60eea4a3a77bfbd6c1334cfca2091f721e34c196cde4f47624bcb90docHeodo
2020-08-11 22:59:12d135bfa839f7aced43217658d78cc59d8c51a7120940e59b3c805612e1b276eedocHeodo
2020-08-11 22:46:440241b1ed7a1656dab5d9fe64b7e59fec547126495769ca53d78220090b494889docHeodo
2020-08-11 22:32:08116d5a4d0b83b31befcc51de658fe9a2a9554ada261572c59be7e4c01a077efddocHeodo
2020-08-11 22:17:5904eb4b28247dcf99dd7a07b62ab41575834d865c72e083dafd8e6b620a6e23cbdocHeodo
2020-08-11 22:02:257100d7486bcccf991906541b709fd020c8cf3aebaed5025f37c19ea15924b034docHeodo
2020-08-11 21:48:165e024e08e0d813ae8a53e1428e482971b0b92dd724030cbc1e80219aebccb455docHeodo
2020-08-11 20:14:5013114e608a7cc05973b50935d669f9bb5a135bee36e1f29a47243cdcb3cd7401docHeodo
2020-08-11 19:57:401bd68b07b524ffb4ddcd903f20522ebbaf7108f9f695e901551f5d4f90013345docHeodo
2020-08-11 19:43:03505bf00a3f0c6b5d8ececc410f78de1bdb0fffc8fe7a3324166448fbb3a213f0docHeodo
2020-08-11 18:12:17e589ae383d2dda4770ca6a4cd98ae21ad8e8230567a0c3c2dd5fe33395d90cefdocHeodo
2020-08-11 17:54:50308dd9d0b4a83eed9cf0f4d5014a22bbb9f37b197d9f8304612cb48397cd5404docHeodo
2020-08-11 17:22:4143dfe63eff9212397ee2b7be571cd22d59ee8e88b32968034a655193a6ff6b71docHeodo
2020-08-11 16:33:59c3832fbc9a1ddc68c6e46a3833639941057f03d5a0382d4987e72a406da4d1dddocHeodo
2020-08-11 16:19:2297e64786b6f45cb34657b58a5c00faaf867ded928d629958e132d0f2a9a55cc9docHeodo
2020-08-11 16:13:04eb49288707c4dcf92d90a2950f435bdbde3de3c0db6b9016085bb36e68ff385cdocHeodo