URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.ni-star.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-03-19 15:12:01 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-05-29 21:13:16 88.218.118.28s-vps-de-589.upress.ioNot listedAS209622 upress-drb- NLyes
2019-04-16 10:35:21 159.89.22.248s-web02-de.upress.ioNot listedAS14061 DIGITALOCEAN-ASN- DEno
2019-03-19 15:12:13 206.81.15.158hosting.viktopia.ioNot listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-11 23:57:05http://www.ni-star.com/wp-includes/xeWa-zvtLPvB...Offlinedoc emotet ext epoch1 Cryptolaemus1
2019-04-11 22:47:03https://www.ni-star.com/wp-includes/xeWa-zvtLPv...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2019-04-10 03:17:52https://www.ni-star.com/wp-includes/file/messag...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1
2019-03-19 23:30:10http://www.ni-star.com/wp-includes/bn00b-si78o-...Offlinedoc emotet ext epoch2 Cryptolaemus1
2019-03-19 15:12:13https://www.ni-star.com/wp-includes/bn00b-si78o...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-13 18:11:380e4cb4664c90b327e9cc3da8b12def365d187ab543b6a840b95458913a17549ejsHeodo
2019-04-13 09:44:340ad1a288380b66bec4c13428d108845caff4201fc46cb0cddb85e4a314da26fcjs Heodo
2019-04-12 21:21:391019bd7e2c3bb1a5b578d7406a74824051d49e84c13864a73635362e7bcbcb4ejs Heodo
2019-04-12 20:49:53396aa84b9eded6ed1fe29b777947f74eab46dbc5d1242ff537079160584577fbdoc Heodo
2019-04-12 19:46:53ee1a33fd81e68eef2c49a0e4b3521bc11d455bbf96fb8360618c6cb120814e85docHeodo
2019-04-12 18:10:5033bce221f8ebe653fde7e60ff88a6965c25463d8d339564d007b5c345c109df7doc Heodo
2019-04-12 17:07:5397f2089d292d618ed0bac5e3ea99a8a8c6df456f7d310c7cf3f900c3eaad7276doc Heodo
2019-04-12 16:04:48342d4017b56faf093f1130c62a4ce9c2c81ba35b7fdf29a2cfc967bcceef4ed0doc Heodo
2019-04-12 15:33:416daa3bc96882673f8d2d74d77c4be3eff3ae5e7f8267fc4025264b4ca1dc1561docHeodo
2019-04-12 14:31:50820f55f3e2fa1dafb602b74f4313e2be47823c17fd6408468c2e787a09c1f5b1doc Heodo
2019-04-12 12:57:3871385013eeac0e820dd304998a035333c09ef48840922c093769dfab353a7eb3doc Heodo
2019-04-12 12:32:349f101483662fc071b7c10f81c64bb34491ca4a877191d464ff46fd94c7247115doc Heodo
2019-04-12 12:01:30ecc0b681983618e43169aea2f5c9ea2e12553058c9af4a02f532489499b116d5doc Heodo
2019-04-12 09:56:26e7cdfc5eb9c981db418815dc459fd06d711ac86e6d83611d972d5e91e621fdf7doc Heodo
2019-04-12 09:00:1796786504ad52978d682b65996187b87e60297bf202a1ef9a9c150a06f0b87e4cdoc Heodo
2019-04-12 08:50:10d194ff91d5c737ca5fb69b24e3118a426e54b65e968824691eb9bd463f6cc4d1doc Heodo
2019-04-12 08:35:28cc55b2720070f6b86d17d3e083f3f364a9256f1193572af0a2642eae047eb57bdoc Heodo
2019-04-12 07:52:26061fd00e92e9bc6a34db2a6ab27dad3ec9f759b34c72146c1f0aa2adc3413de7doc Heodo
2019-04-12 07:38:20609fffab37310c162348ebbf3b967e490753d85d08ad725863f98d9cc87582c6doc Heodo
2019-04-12 07:07:335017ececeb4d4f7c8483dd8178df693760ad227e94053b560ac60cd81870b199doc Heodo
2019-04-12 06:57:18bb96f404b090c1e4c7853dadaad4846d135969a401747c87ee93b760fc844331doc Heodo
2019-04-12 06:47:158fa2a91359b44c86c77775b3227c8ae0ccf1f882dafaa3309d0b8fb315437274doc Heodo
2019-04-11 22:47:03b6cfe1983ff1d2fb772c8e68fcbd69f805d5b488ded023a6c13de39965af95f6js Heodo
2019-04-10 20:29:257d91ca89ded649dd8a7f691d603d22435d13fc741a7d78b3f587b18370184029js Heodo
2019-04-10 13:49:17c5aa88145481b5ec57a620084e533210b7d896e4b5f7b4aca8abdb68646a8343js Heodo
2019-04-10 07:18:0820f61d43bb940c959db46366a7210ec321b90552f17e6bf3502bb26b5490ded2js Heodo
2019-04-10 03:17:5277c98ff712a343ccc9112da423212287d0111a63c6ddb750ba49866b8e48a0cejs  
2019-03-20 19:44:37869f09c1b430433a385b4ec13a90eef4cfe0cba092a46fe71107de2f865bdf0ejs Heodo