URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: vitaecbe.rxhitech.com
Domain registrar:Public Domain Registry -
Domain registration date:2020-08-05 16:47:36 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 17:36:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-25 01:43:27 204.11.56.48SBL494567AS40034 CONFLUENCE-NETWORK-INC- VGno
2022-08-06 07:28:46 209.99.40.222209-99-40-222.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno
2022-01-11 17:36:03 136.243.92.92server540.iseencloud.netNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 17:36:04http://vitaecbe.rxhitech.com/wp-admin/344427_97...Offlinedoc emotet ext epoch5 heodo ext Cryptolaemus1
2022-01-11 17:36:03http://vitaecbe.rxhitech.com/wp-admin/344427_97...Offlineemotet ext epoch5 redir-doc xls waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-11 17:36:042b74c0929571e7b9661c5b0cf19559b2927a2e48ecbcda6d743144d34b7151ccxlsmHeodo
2022-01-11 17:36:03be2095375529e87236664cb43f7da83ad3cbf52c88682a537a5960a3f0f02915html