URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: zl-partners.com
Domain registrar:eNom -
Domain registration date:2020-04-20 10:49:51 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-05-17 13:06:04 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-25 03:04:09 192.250.227.25s1100.usc1.mysecurecloudhost.comNot listedAS36454 WHG-DAL- USyes
2025-04-28 00:05:31 65.181.111.235s1358.use1.mysecurecloudhost.comNot listedAS14670 WHG-USE1- USno
2023-05-17 13:06:07 204.93.169.73mocha3032-web.mochahost.comNot listedAS23352 SERVERCENTRAL- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-05-17 13:06:07https://zl-partners.com/es/?1OfflineBB28 geofenced js Qakbot ext Quakbot ext USA Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-05-18 17:28:47bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780js  
2023-05-18 17:01:0751ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4js 
2023-05-18 14:23:31a2222ce8d0e97a87df66504d71e8092a824ba19249764ffbfbd6854a741ba1d5js  
2023-05-18 12:39:489b2f8c74295c1bedca1e85a34eca84634c652741d93c24d9c5586926552a77a5js Quakbot
2023-05-18 11:09:4553182e2434b52d11490f911c908c6c23755d667fca1a03ac5d4be2cc9b0cd61djs Quakbot
2023-05-18 09:20:08f91b22ef75c62115177abfa54ffc898319098f3de31ddf0b2a964dae96c3b376js Quakbot
2023-05-18 06:39:489be436ae8d8612af572358c0394b27e9c751e6f50b2597c2b7ae636e99088255js  
2023-05-18 06:30:44bc08bfae3a441cb9485634aeda5f5ae4cbbe5e36cd98ce7b2812cd62ed4e5034js  
2023-05-18 04:33:54285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544js Quakbot
2023-05-18 04:28:285f98b59055620e884f40e504321e65af6a6ff2e7eff1035ff136dc57e98e0cb1js Quakbot
2023-05-18 00:56:39819c3375d47e95f26e1466039e2ff5a096837d0761bed7564c2366b094c8895bjs  
2023-05-17 23:23:29981c8836ca3485400bc8fa7a73067986d2347ba02a058d61f1ee31be71d09a3cjs Quakbot
2023-05-17 21:27:5517da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cjs Quakbot
2023-05-17 20:30:33fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47js Quakbot
2023-05-17 18:28:128b2b3c3498bea970b5883a908b36e4437b9809a010cf2df44004264d33d66dbdjs Quakbot
2023-05-17 16:57:50cd8a39cd43a8cbb2e0c04b201b7df230226fe2dd696ab5c20c9ecbb16cc723f3js Quakbot
2023-05-17 15:01:54076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89js Quakbot
2023-05-17 13:06:07e98ab08e4897807987344800297aa41a72fc207a57b0e89510243b3b8ad0e144js Quakbot