URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: zlomex.fun
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-17 21:46:09 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-17 21:46:10 54.38.139.22Not listedAS16276 OVH- PLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-17 21:46:10http://zlomex.fun/cgi-bin/bx4play3ka_phda82x8_b...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-18 06:41:39b532ca1d80293700b173d821d788d7f1a27d7a9cbc5b8e83aa351dd69e0fbd5cdocHeodo
2020-08-18 06:19:374cc1cdbdd17e8f0b7cb09725937c61cb74bab089ccd7249d8198c12f62b0c857docHeodo
2020-08-18 06:03:5326919d2560f6e6e4b5c44add2fdda04f676163a1085799bfcacaec874289f126docHeodo
2020-08-18 05:49:46a7c86fe81531f07b7120be70ff6f16519758654ccc7ae3c901cea8d36e3a21c9docHeodo
2020-08-18 05:36:381b091450a22052f2f93d1729f74b3ceeae074536055865f9e232398acd2f3a7ddocHeodo
2020-08-18 05:18:083b916aa5cf96d7330d89f1de96c84ecc9f5acb0f21832d5571cdfe9fcc0b069ddocHeodo
2020-08-18 05:00:5481ec297e1363823b4a4170387a248d68e35aaefafcd998d0f30c090fdb0a7ee8docHeodo
2020-08-18 04:44:524a49fe6ff5e8731a7aa0536b8f0c0dbc5673dae67c35f0141efb3807cb21dadddocHeodo
2020-08-18 04:28:49f3155524e3a1006204ec5ef83349e5fa2fcdf663c69d598cdbd5cda6a378a0b9docHeodo
2020-08-18 04:06:1523866d5c01d81dae8b6112cf09cb195b3caeab201b8d5b2074c6c01e280d1783docHeodo
2020-08-18 03:55:401c62113735e6ddecc264c05212144be5441448de6c9cdc063a1d3ff2494185a7docHeodo
2020-08-18 03:47:519f6acf9a0b1abf9481a13650ecdec0e7a9cb7a4c30938c2ffcca8da0934a96d2docHeodo
2020-08-18 03:28:481a92578592df96f6bc3c58861c8719f37bd57d2386789d07d319c613fcf2f79bdocHeodo
2020-08-18 03:00:1777893a46e331faf345a8134849c0182109a90c65f156f288b95f054bc8bf667ddocHeodo
2020-08-18 02:45:1278159b47ee6e43a81e5f727e9f01d56700fb22cca0c9f6cde333e91c0130dee3docHeodo
2020-08-18 01:53:59cbae984f113307015e9a42c646507cd4fecbc37c1ce7ed2fa9d731fdfff7e00fdocHeodo
2020-08-18 01:39:10872c0c3578f24be338bcaa8a29f2b157d80a2d3d5e5ecbd33b028bced714c077docHeodo
2020-08-18 01:23:12c84240ca9f8d00a5e32e190c4fc4a4728fe5ca1e12603cf78a77ce78b9f69d72docHeodo
2020-08-18 01:09:074426143a003042fcf53c32a42cb6e2dfa30ff4dfdf7e2248eb6533df67ac8723docHeodo
2020-08-18 00:55:14cfe5cae34d529a71812a66cb3d6f2e9b2b7446bf4ece6aeae5c32c9cb325ce7adocHeodo
2020-08-18 00:41:1492bd87c0eed15bf75f7c61b1879280e25a7997a4afe7c804c82a3902f51d46c1docHeodo
2020-08-18 00:21:428bbfe9b6aae9ae8cd42ef61b046d0c690f0637f216d5a22d4a5f7911b59469f7docHeodo
2020-08-18 00:07:51e976f7e4de4c0bedc4e4bbc27752994f9110c050508b106611f035260551a8e0docHeodo
2020-08-17 23:55:15e997b17d809b4d63590d7b7cca81318d3ecd18b59a46a4e83d88af6dfaeba54bdoc Heodo
2020-08-17 23:41:482e363ae514de57da55513b7e9b5499e658bb254447ad4bac734032c94faed259docHeodo
2020-08-17 23:28:0732cb1657bab6cea4734f694fefe16389dca17cad7673cc0be676c77e070ae735doc Heodo
2020-08-17 23:15:23c5e15f4b4f97c4a8ab87e6bd09bf057455834577a7180163ca978fb734c66961docHeodo
2020-08-17 23:01:516535313a52f000bc92afec62f22968677544878c5cf2109e862e72f7c441dda0doc Heodo
2020-08-17 22:48:47818e631aced6291b95a641f2eace827a0b9f2ee202b364a3a09378bc52401e03docHeodo
2020-08-17 22:35:311c00d01cd184a0d2a13e0b10fc17fe857ee0c55fe6894a8a538685b2c7a9150fdocHeodo
2020-08-17 21:46:1028be508a00c3db077ca8f4a78784ca44bcc58cdd1a37d988c56d08c777f5ade6docHeodo