URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host zafado.com.

Database Entry


Host:zafado.com
Spamhaus DBL:Not listed
SURBL:Not listed
Firstseen:2018-05-07 20:25:16 UTC

IP addresses


The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-05-07 20:25:43184.168.152.147p3nw8shg280.shr.prod.phx3.secureserver.netNot listedAS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2018-06-25 20:24:22http://zafado.com/aspnet_client/Statement/Invoice-352794/Offlinedoc emotet heodo CleanAnonymous
2018-06-22 07:27:35http://zafado.com/aspnet_client/Jun2018/Services-06-21-18...Offlineheodo Clean@p5yb34m
2018-06-18 22:31:03http://zafado.com/aspnet_client/zWDjgqBG/Offlineemotet epoch1 heodo payload Clean@JRoosen
2018-06-15 06:03:10http://zafado.com/aspnet_client/ACCOUNT/Invoice-06-12-18Offlinedoc emotet heodo Clean@DecayPotato
2018-06-12 13:51:28http://zafado.com/aspnet_client/ACCOUNT/Invoice-06-12-18/Offlinedoc emotet Formbook heodo Clean@JRoosen
2018-06-08 15:55:03http://zafado.com/aspnet_client/ACCOUNT/Please-pull-invoi...Offlinedoc emotet epoch1 heodo Clean@JRoosen
2018-06-05 16:24:07http://zafado.com/aspnet_client/RECHNUNG/Rechnungszahlung/Offlinedoc emotet heodo Clean@JRoosen
2018-05-23 20:39:04http://zafado.com/aspnet_client/ups.com/WebTracking/ZSU-0...Offlinedoc emotet heodo Clean@c_APT_ure
2018-05-16 14:31:40http://zafado.com/aspnet_client/o4yd0Z06/Offlineemotet exe heodo Clean@c_APT_ure
2018-05-07 20:25:43http://zafado.com/aspnet_client/QjpcIfUPLy9CP/Offlinedoc emotet Clean@JRoosen