URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: tier-2.desevens.com.ng
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-17 14:34:09 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-01-17 14:34:14 169.255.57.93cp-ng3.web4africa.netNot listedAS327813 HA-VPS-NET- NGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-24 05:25:37http://tier-2.desevens.com.ng/wp-content/EaAQXxUB/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-01-17 14:34:14http://tier-2.desevens.com.ng/wp-content/YIKscDWO/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-25 01:27:01983ddd1518361a6f16f1b4f4980f9f8e195ab46794ddb14935f83c5a93781f17docHeodo
2020-01-25 00:26:002b5ca64e42cef50cfb9ace4245c80f04386d418c75fca3e1936a02b03f2b9690doc  
2020-01-24 23:52:4575014b9efcb14fb22591a986fdf636d6106b987d956ebbf793aa91c24dd67dc8docHeodo
2020-01-24 23:24:5392e56c8d6f6630b9d9bbf2083ea377ae3f9600b6b452ae0740dc18902d49e2a3doc Heodo
2020-01-24 21:54:0008dc77e69042d7af86f3dc5a4e4d3299c852b20b5b50091892ad7f0e1eebd7c8doc  
2020-01-24 21:04:44f514a1b466096bf3207af00185674482d598f536c8bc2fb78216494aa14d3ce9doc Heodo
2020-01-24 20:51:134982421b347ca1f4b3ad1ffc6c6bbbef2ad9fb126ef18e2db576a1a5bdc39163doc Heodo
2020-01-24 15:36:372d4faab5324229be37231e2fc6d6b430579e396fcdf4db46867cf7f7b04e90f5doc Heodo
2020-01-24 14:05:3091716865af6c80fca3ecac4d0d46ce403b4e7374fd8b651d19a1b98d4ae55b93doc Heodo
2020-01-24 12:40:00863f355a4912ee86d8ce6aa0b98ad27034bc55650b9ad5b47e1a3ecc5cc4d90bdoc Heodo
2020-01-24 11:07:500410a5d9885db43d1b91eb836ab2e33102eec96ec006db3ac01737fd6e10ca5ddoc Heodo
2020-01-24 09:36:5121ed646e9c73d65b5355a50adb7b3a7b2f6d76b45d4248e2ad2480fd784ee8b5doc Heodo
2020-01-24 09:19:18ec33bf8f58aa91fab9e04fe9b8ff924c656ddb9921691b11dbf291dfb37afcd9doc Heodo
2020-01-24 08:05:55829533600afafde7716701f0ea4bc0cb998fbd85124cda950547315d1c512adedoc Heodo
2020-01-24 05:25:377c181b5800d9b531de9f431cbd6947e93f55ac0e5f6fcad200acf2466f411a8cdoc Heodo