URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.servuspress.ro
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-31 13:09:04 UTC
Total malware sites :1
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-18 14:54:34 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-09-18 14:54:34 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-09-20 12:58:15 104.21.1.96Not listedAS13335 CLOUDFLARENETn/ano
2025-09-20 12:58:15 172.67.128.250Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.112.1Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.16.1Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.32.1Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.48.1Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.64.1Not listedAS13335 CLOUDFLARENETn/ano
2025-08-09 09:43:31 104.21.80.1SBL681411AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-31 13:09:05https://www.servuspress.ro/cgi-bin/Reporting/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-02-01 08:41:398ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0docx 
2020-02-01 07:12:24da2dfdde77d319fa7d1a1326ca2ce99142a8d194e609eba08264875f442e240bdocx  
2020-02-01 05:59:0833a89c876ed4c1f54ac3ebf60cd427562e652b39263734b693beb3be9e6c67ebdocx  
2020-02-01 04:35:11ac59c732daa8085badba3321495b6415cec136aaceaf03e509380f2d2742866bdocx  
2020-02-01 03:22:36c117593f754a9dafdfb9c3bcaf46d70eda6bedf7ee811038f00aad85aa541355docx Heodo
2020-02-01 02:00:097e702ae9bf205d1285af80c992428c4c748c6c50e07571916481437c9ca70609doc  
2020-02-01 01:00:225403de32b87a8204b4a1dfb11eb188a2a0614d3d7e34794fa33bccee7e84ebc1docx Heodo
2020-02-01 00:11:187adf027cfbacb9e234e80ea5563bb9f7e1dcd003c562a6964c9c65524abcf3d4docxHeodo
2020-02-01 00:01:3047914796d5d3ceb124dde6e14b62617568efb43c06cfc35eb0614c0ee96658e8doc Heodo
2020-01-31 23:14:3934fa1227f7140a4738f187b9e0a6d1eb440f57b91eafa01c146f3200287b075ddoc Heodo
2020-01-31 21:22:528f51de1c80475c0ce51fb6e405306b5845df6771b3160797752e26abeec172ffdoc Heodo
2020-01-31 21:07:209acde9478f827a67975691003ecb6ff2b7e1c319a38ba4ae94e40804654cacd0docx  
2020-01-31 19:51:2677863724dd91af4ef0faf3ac63c9c34e7506270efef4ab9927609445c80609e7doc  
2020-01-31 18:20:499ca9749660569bd45851774becb4204394ea2ab1cb510d28d7bc77060aee9c20doc  
2020-01-31 16:48:28c65e54d8fe1847d0d081c3058842c5b0254a355c41756816944d2fb8fcf08a54docx Heodo
2020-01-31 15:24:33dbbe1fec47e8d343db79a96fe58ee5a504609dbddad0587cb31c83d134d02972docx Heodo
2020-01-31 14:08:45100f39e84287ca9ea977d399fe1135ab34bf7c244cbb9c14408f8255c3538d85doc  
2020-01-31 13:09:05377c5063ac5bc848f3d25e018ba80d745be7c45e27d25749ffe648f38ea7a1c1docx Heodo