URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.etelefon.ro
Domain registrar: n/a
Domain registration date:2010-06-28 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-11-11 18:14:16 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-29 21:10:28 185.53.178.99Not listedAS61969 TEAMINTERNET-AS- DEyes
2025-05-07 18:49:53 185.53.177.54Not listedAS61969 TEAMINTERNET-AS- DEno
2022-11-11 18:14:20 173.212.230.222vps.rosms.euNot listedAS51167 CONTABO- FRno
2025-10-18 00:39:12 104.247.81.54Not listedAS206834 TEAMINTERNET-CA-AS- CAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-11-11 18:14:20http://www.etelefon.ro/docs/csv_import/Njpcdo0x...Offlinedll emotet ext epoch5 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-11-12 19:55:24b0b8d2518fe1787f7b8a00482e638bd6e9dc0e6510fb15b5f853f6f391324222dll Heodo
2022-11-12 19:33:179cc3a8a6debef0747496d8a1a4be6b07960b7610a4d1a15fb00194555c8d012fdll Heodo
2022-11-12 18:42:361d8ddcc3f798acf57fc288ace7e8c115ea2bfb0ef8254fa4e1536826f4bbaf9edll Heodo
2022-11-12 17:28:154779367f55e9c3ad75ddfd2138d4db240094fd5fd139bf69aa9c08f7fba850f4dllHeodo
2022-11-12 17:05:57d99c3de4ba00eddca99479ef0d9f75266399c4ae700e5a81915f671380264889dll Heodo
2022-11-12 16:28:47fd8468a1e355ea6da60c5ae8d27d09d05d05d39f528d10edc965495043fd342adll Heodo
2022-11-12 15:02:55c193e3e641c9c3973a8b25bdf729c6c006e299dc364687af235f4f86cb5e74b8dll Heodo
2022-11-12 14:39:20655c3e1eba10190ccaea07daf00ba73527a46c12b1f8cc4e8aee63fbe9ea6b30dll Heodo
2022-11-12 09:21:52aa81d0b912027217b0afac92e79022d583c16af0cbcb0b5841560bff0d5df453dll Heodo
2022-11-12 08:56:49368f97f9b7802f6cb9ca8fec21ae1db3350d4bf23ad4f65a11bce2a276959625dll Heodo
2022-11-12 07:33:487e29eeb25039cbad035e25fb129ed8b06f4b90abaadf16787f45bb4f6149298edll Heodo
2022-11-12 07:11:299b34768c3fd0b98e8d0205c04a3f865aace94e5825547837425b2a5a5e1e9460dll Heodo
2022-11-12 05:34:359241a3bfabefcf78ded51e74644b907973ccd6443b4c90690680b5dedef69b8adll Heodo
2022-11-12 04:51:248d961992886ba6ce71a5728f5015af851071896bf607bdca7415c1ed09763e3edll Heodo
2022-11-12 04:22:29e64a8ddd6f17915d4264dfe9d8cbbcabb32a25410ee3bacb6e117c37667a2aa5dll Heodo
2022-11-12 03:32:5544efff85c87dc507883dee204f3f9070d00992c7eceef31008f1e0e17c94a5b3dll Heodo
2022-11-12 02:11:182ee3d858e13d4128fcac397a40ebf194d5b622cb8e58af2c6cdf819578094c7edll Heodo
2022-11-12 01:31:378a293a1ebb64ad7972b26d161650c236d8302f545ed5fb9298292487912e2522dll Heodo
2022-11-12 00:35:416b51fdfb9a70de3585c3468e728b8a6b332013f6c4ca78520708d5d250b51bf9dll Heodo
2022-11-11 23:48:25c61302589a3bb3590a96fd6bd37f0fb80a240b01cf3a5c1ab3e07419cc84aa39dll Heodo
2022-11-11 22:30:097cacc7f3efb33d28812b41c3efa7d6d2dcdd6b4f2e729f3aeff7da1b3bafb690dll Heodo
2022-11-11 21:34:2674db0d59cfc8c05a3ae823ec9765dc13ff724ede0552a020eee0e9c5e446d563dll Heodo
2022-11-11 21:17:48a5455c9b4c47691cf3a6ac0728b45835a210567949198c1caae985790bece7ebdllHeodo
2022-11-11 20:28:141490b1c9ffdd7266b02460590c95f3ef0b6bc154f5ec3aa7c201acc763858852dll Heodo
2022-11-11 19:31:53700622add31642369615e1f7c0fdea1402af1a7a7efe034aaf02953c46591d06dll Heodo
2022-11-11 18:14:20549a2930ae8ba67381fd117ef74dcc62fb203c53ab9635fcbf62e1a02a54c75adll Heodo