URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: thinglabs.xyz
Domain registrar:Namecheap -
Domain registration date:2021-10-27 14:36:56 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-02 22:43:08 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-02 22:43:15 104.21.29.100Not listedAS13335 CLOUDFLARENETn/ano
2021-12-02 22:43:15 172.67.148.191Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-02 22:43:15http://thinglabs.xyz/overcollar/s4rNtArh/Offlinedll emotet ext epoch4 heodo ext waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-03 12:53:4316211b428f9d5da08b3a0d77589bf217f34558388d52d294f7d37dfe5e44b2e0dllHeodo
2021-12-03 11:59:0772856a1bde8683ad1eb96f61aeea52fef754c48efcc76de806d8b6990821aeb1dllHeodo
2021-12-03 03:36:42a100ff92517576acf503e784e1d6244ed50fefaa881d33069eabb984b731d02edllHeodo
2021-12-03 03:05:50a927cf5b92837ff59e4c8c366fe47798686d77164d5e6fbe7732b894516c8e65dll Heodo
2021-12-03 02:45:306e91ab48ee46d6834d44a88f0b61674f6dc7b067af789e26c53d09bbe06faedfdll Heodo
2021-12-03 02:33:35fa1f0450557d9c8f25559f30921d92b966693f03a60e02564ea291f3db39ffc4dll Heodo
2021-12-03 02:15:05d3e93b7c34b6572788b26ebcb3cc55cf099af40ef3c50953278b5099d1946623dll Heodo
2021-12-03 02:00:50b955610ea5d85d1dbc95a3e006df3dfba4adf413360cb991bdc4ff2cf1be397bdll Heodo
2021-12-03 01:45:573e4fe6cc2f144a91fea43fb703c480d43d12568fc08480f52b1827d0b326aa96dll Heodo
2021-12-03 01:26:51cafae53a0e4bfec3563f4022bf20b1cdc162d4323c8fc581093ca213a8ad5deedll Heodo
2021-12-03 01:17:19e13b19f1a78bce9b5d29f160d5ebec2b70ead466b5236244b9ea967f0be5672cdll Heodo
2021-12-03 00:55:347834875391cbbcfa83693f22cc7f0fbf27a3d36401268bcc505bbc384782d4aadll Heodo
2021-12-03 00:38:271809f68e8f2bd0acd153ff7116f94b82dd255f000661cadff5b41855a12cbbf9dll Heodo
2021-12-03 00:25:292523bdafbd3c9a94b1ed72a4696ba8638b42bf9a32d5a8084af1b471e6a4f959dll Heodo
2021-12-03 00:21:58be8ed0eedbf25d9d8aa1ce5b0e7585bad0ff03ff70ab7a825ec7acd7d8f57275dll Heodo
2021-12-03 00:11:24722a6bd5f09cbd16880f8a089362c229198ff99fdbea6692aeb77c776ff24c1adll Heodo
2021-12-02 23:26:19fd45f9c49a02c178acbbe9262003b5b2a9ee9393505af7bcf1bb1a66b2040e54dll Heodo
2021-12-02 23:04:4813cce288cf5ee7e304fa935a4a74b595ed338da0090e771c21c7bb4e232d40a3dll Heodo
2021-12-02 22:57:51413019e089befbca507a12027f88e021e53e370075cbf2a3f4bb3c9d37e027b8dll Heodo
2021-12-02 22:43:15c3e834edb5f8766b9f2062065e5a63fafb808a8893ea63a3cbd42c705a9f9c37dll Heodo