URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: zirrimarra.eus
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-14 22:58:04 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-02 05:08:22 82.223.15.70ssd5.k3bone.netNot listedAS8560 IONOS-AS- ESyes
2020-10-14 22:58:06 45.76.141.24745.76.141.247.vultrusercontent.comNot listedAS20473 AS-VULTR- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-14 22:58:06https://zirrimarra.eus/wp-content/Documentation...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-16 07:39:56e6896dad4ee0bc73a3114762b88c9d93732c631e64c537334ac38f7c7c421141docHeodo
2020-10-15 05:08:46599c5a96c48cab303ee9a8fedda331cf66f2db8f076733cf715d00c5c4278e20docHeodo
2020-10-15 05:04:1109b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbdocHeodo
2020-10-15 04:55:5109ca73e0406c4d96a73cbaa68660617439ee99224d2603caf1610dd5cad5cb25docHeodo
2020-10-15 04:35:074daef1037d2e8f34834dfda50a4bc9fd7b5e30aea3c2d6b666d85824bb90d79ddocHeodo
2020-10-15 04:14:24826df3430c822b2aa33180efdc56c45a6a2e76c53620a4956652785a354fe744docHeodo
2020-10-15 03:20:5303afbf9b046ee6d340253662dfb45f59e4fb6e75b28dd8bf52bb8becb58145b0docHeodo
2020-10-15 02:50:50fc4e851464b275cb4206af8ce176350c7e12b7b1334a795cf27e48bb6cd9df06docHeodo
2020-10-15 02:35:520cf59450f4af8123dc62d34cb387c1f4bcc5a3c38cd4c966acbd7552574d9fc8docHeodo
2020-10-15 02:21:26100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533docHeodo
2020-10-15 01:56:5092a930cc35f0b758afa1eb48adbd009a241f19b3a1e5a10f2fda6b5495256eebdocHeodo
2020-10-15 01:39:18a9e9fd09c8758fd9bc32c4f3cdc9b19afafdeb894a288778c2a4df42944be7c0docHeodo
2020-10-15 01:14:42cca3799a5d79aad049795ea6a869e22d90d248ef1c1193d5d5933237b20157c5docHeodo
2020-10-15 00:54:18275d247b675319a0e083b29b0e1c88b3bae28687e80b83a5b6db109ae72d954ddocHeodo
2020-10-15 00:42:460ce691ae2caab090785a0378e42e72fb8c1b6e129c8b3f50e32462295cf128e3docHeodo
2020-10-15 00:22:52f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5docHeodo
2020-10-14 23:58:15b1380f1fdf3f7636d79043feef8f62d1f57ec8694f3abddce522899895cf4ddddocHeodo
2020-10-14 23:28:419c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811docHeodo
2020-10-14 23:12:3590e36d2990e1c86b71a77c96196d4fbe57e9e5d274d37bd085edf57d4058a55bdocHeodo
2020-10-14 22:58:05e373aeaa39d4efff72593a5b0a30b797679037516c98a1f6fa3deb3f5fc6bd74docHeodo