URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.maskweb.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-11 15:52:05 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:56:56 185.8.173.240s358.bitcommand.comNot listedAS60631 PARVASYSTEM- IRyes
2020-08-24 16:36:48 164.138.21.218ns83.azaranweb.comNot listedAS59431 RAV-NET-01- IRno
2020-08-11 15:52:07 185.143.233.5Not listedAS205585 ARVANCLOUD-CDN-IR- IRno
2020-08-11 15:52:07 185.143.234.5Not listedAS205585 ARVANCLOUD-CDN-IR- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-11 15:52:07https://www.maskweb.ir/Content/oAQwf-fWm4s9tQyu...Offlinedoc emotet ext epoch1 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-14 00:46:4379c47358c6ca784a93b378478cf157a96b6810484e3fa17d544d8ab047274c17docHeodo
2020-08-11 22:56:49d135bfa839f7aced43217658d78cc59d8c51a7120940e59b3c805612e1b276eedocHeodo
2020-08-11 22:50:260241b1ed7a1656dab5d9fe64b7e59fec547126495769ca53d78220090b494889docHeodo
2020-08-11 22:32:12116d5a4d0b83b31befcc51de658fe9a2a9554ada261572c59be7e4c01a077efddocHeodo
2020-08-11 22:19:3404eb4b28247dcf99dd7a07b62ab41575834d865c72e083dafd8e6b620a6e23cbdocHeodo
2020-08-11 22:02:167100d7486bcccf991906541b709fd020c8cf3aebaed5025f37c19ea15924b034docHeodo
2020-08-11 21:46:445e024e08e0d813ae8a53e1428e482971b0b92dd724030cbc1e80219aebccb455docHeodo
2020-08-11 20:14:5113114e608a7cc05973b50935d669f9bb5a135bee36e1f29a47243cdcb3cd7401docHeodo
2020-08-11 19:57:331bd68b07b524ffb4ddcd903f20522ebbaf7108f9f695e901551f5d4f90013345docHeodo
2020-08-11 19:44:24505bf00a3f0c6b5d8ececc410f78de1bdb0fffc8fe7a3324166448fbb3a213f0docHeodo
2020-08-11 18:12:43e589ae383d2dda4770ca6a4cd98ae21ad8e8230567a0c3c2dd5fe33395d90cefdocHeodo
2020-08-11 17:55:40308dd9d0b4a83eed9cf0f4d5014a22bbb9f37b197d9f8304612cb48397cd5404docHeodo
2020-08-11 17:40:3241a14ae8992338c85b383362556c69ed34ef79be6782f91011a521681efea640docHeodo
2020-08-11 17:22:4843dfe63eff9212397ee2b7be571cd22d59ee8e88b32968034a655193a6ff6b71docHeodo
2020-08-11 16:44:56eceee3a8316d96e7e391178028416a764a5aa0eab8dcf94f1ec6af4f5ad3d977docHeodo
2020-08-11 16:33:50c3832fbc9a1ddc68c6e46a3833639941057f03d5a0382d4987e72a406da4d1dddocHeodo
2020-08-11 16:18:47d2d1169820bcf260d48e6273ea105b4db9727fcaf8702362a7c8d3b8ca93b1b6docHeodo
2020-08-11 15:52:07bef25908178e50a5ea5c9427e2d767e442719458414443980f1d1454659d4804docHeodo