URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ufapro888s.info
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-12 22:39:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :31

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:40:20 104.21.5.173Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 09:40:20 172.67.133.170Not listedAS13335 CLOUDFLARENETn/ayes
2021-10-11 11:11:58 46.101.121.244Not listedAS14061 DIGITALOCEAN-ASN- DEno
2021-11-30 23:59:02 18.193.26.52ec2-18-193-26-52.eu-central-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- DEno
2021-10-08 08:08:25 3.125.252.47ec2-3-125-252-47.eu-central-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- DEno
2021-10-05 12:03:33 206.189.50.60Not listedAS14061 DIGITALOCEAN-ASN- DEno
2021-10-06 12:26:11 206.189.52.23prod.greengorych.ruNot listedAS14061 DIGITALOCEAN-ASN- DEno
2021-10-07 12:17:27 206.189.50.215Not listedAS14061 DIGITALOCEAN-ASN- DEno
2021-10-05 00:02:36 161.35.218.92daftarslot88.xyzNot listedAS14061 DIGITALOCEAN-ASN- DEno
2021-10-09 03:43:05 167.99.246.105Not listedAS14061 DIGITALOCEAN-ASN- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-13 23:44:03http://ufapro888s.info/cgi-bin/zsYdbCOamS1IMFX3...Offlinedoc emotet ext epoch2 Cryptolaemus1
2021-01-12 22:40:06https://ufapro888s.info/cgi-bin/zsYdbCOamS1IMFX...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-13 02:12:153d0f797849969d919b2a23e7c8b525550fb34076e60df60ab4e380fff6c8f9f4docHeodo
2021-01-13 01:57:076519108ab0d32b865e06f74784831341df7a5c7a0f02221511a5a13b8762e375docHeodo
2021-01-13 01:41:00c1386cfa76e20ef89543333e71c40fdbbec97db19367409d0d96bd4fe370ff30docHeodo
2021-01-13 01:36:20d2232dfab1a3d97b00285d3baeedaff80ee090c7fb8bec50f6fb23554fc7d4aadocHeodo
2021-01-13 01:19:51d77e78f619d681603f2d2c3ecc803419724067121e18623302a4155a0efba1fbdocHeodo
2021-01-13 01:07:476531485e7908b63b71fed89fd7a5e90a7d0250b15f1f9f25552776518ecf1b94docHeodo
2021-01-13 00:54:298d5c3655c17e7b52765884c6c65f4accd5e2d174f1b28c4a9a25b5b3686c50b7docHeodo
2021-01-13 00:41:03b80739d7b435e5a620e5c121269e1f8a2050a87d1a4d6b934107346c62d09ddcdocHeodo
2021-01-13 00:21:565e1578d0acac3625f838389363b6e3d5ee3b946ce7ecc681ba00d134eb4ff07cdocHeodo
2021-01-13 00:12:01d537bf50ec4b548ea84743bd82fca89f61456fdabd24530cb04214c8d7fe7043docHeodo
2021-01-12 23:59:40fa94db36e6f47c1aaf4d141055594716287ceb31cfd4b5ce0ab5c350cffc7969docHeodo
2021-01-12 23:44:0982cbebfcfcfbdd97e4f714428e572c4f2320187eac194b733816109c957e9505docHeodo
2021-01-12 23:29:51bd45f2cb32d66093175c05e0b8e9060fbcc0fcaca57454dfab3abf0d54711f13docHeodo
2021-01-12 23:08:3521b5c730d1a2cf87f14e0e687f6ade375e751a5705d59995b7b373756ef20e93docHeodo
2021-01-12 22:53:010f2701f8a2887d860bdb0dfe233f7e25ee8852103dc87658ff1b67b34a1c30b7docHeodo
2021-01-12 22:40:06988a420c56f820f5165a56b7d242998ef580c2191ef089928aec599f8732533ddocHeodo