############################################################################## # URLhaus ASN CSV Feed # # Generated on 2026-04-28 03:33:42 UTC # # # # For questions please refer to: # # https://urlhaus.abuse.ch/feeds/ # ############################################################################## # # Feed generated for AS139880 # # Dateadded (UTC),URL,URL_status,Threat,Tags,Host,IPaddress,ASnumber,Country "2026-02-16 10:02:25","https://m.meta-dm.com/file/ueditor/php/upload/file/20250114/x1/REF-CLI%20v1.0.3.exe","online","malware_download","","m.meta-dm.com","156.253.32.122","139880","SC" "2025-12-15 09:47:15","http://zycdjz.com/editor%E6%B1%89%E5%8C%96%E7%89%88.rar","online","malware_download","","zycdjz.com","107.151.212.80","139880","US" "2025-12-12 17:59:08","http://204.77.130.20/02.08.2022.exe","offline","malware_download","censys|CobaltStrike","204.77.130.20","204.77.130.20","139880","US" "2024-09-19 14:53:06","http://els.ststst.top:8080/bins.zip","offline","malware_download","Mirai|zip","els.ststst.top","154.209.166.232","139880","HK" "2022-09-03 05:15:06","http://petroaryalivco.com/dining%20delightk.exe","offline","malware_download","32|exe","petroaryalivco.com","154.82.61.248","139880","US" "2022-09-03 04:55:05","http://petroaryalivco.com/documento2.exe","offline","malware_download","32|exe|njrat","petroaryalivco.com","154.82.61.248","139880","US" "2022-09-03 04:54:05","http://petroaryalivco.com/Envio25.exe","offline","malware_download","32|exe","petroaryalivco.com","154.82.61.248","139880","US" "2022-09-02 19:04:05","http://petroaryalivco.com/nj25.exe","offline","malware_download","exe|njrat","petroaryalivco.com","154.82.61.248","139880","US" "2022-01-21 05:35:05","http://mrkingcake.com/wp-includes/EUS-1758/","offline","malware_download","emotet|epoch5|redir-doc|xls","mrkingcake.com","156.227.93.60","139880","SC" "2022-01-21 05:35:05","http://mrkingcake.com/wp-includes/EUS-1758/?i=1","offline","malware_download","doc|emotet|epoch5|Heodo","mrkingcake.com","156.227.93.60","139880","SC" "2021-12-04 00:32:09","https://www.bboprecords.com/cgi-bin/7e0tqBPK/","offline","malware_download","doc|emotet|epoch4|Heodo","www.bboprecords.com","154.209.173.35","139880","HK" "2021-12-01 19:33:09","https://www.bboprecords.com/cgi-bin/ucFtWWFliu/","offline","malware_download","emotet|epoch4|redir-appinstaller","www.bboprecords.com","154.209.173.35","139880","HK" "2021-11-26 23:59:08","http://vote.creativedune.com/wp-includes/c5AxiMo5/","offline","malware_download","doc|emotet|epoch4|redir-appinstaller","vote.creativedune.com","154.199.34.133","139880","SC" "2021-01-22 09:07:07","http://www.wangke9.com/wp-includes/dCmiSx8y/","offline","malware_download","emotet|epoch3|exe|heodo","www.wangke9.com","154.209.163.216","139880","HK" "2021-01-12 16:16:07","http://h5.ashiwenhua.cn/louis.php","offline","malware_download","","h5.ashiwenhua.cn","45.204.239.173","139880","SC" "2021-01-04 22:59:15","http://thinkbrief.cn/wp-includes/i/","offline","malware_download","emotet|epoch2|exe|heodo","thinkbrief.cn","156.254.42.14","139880","HK" "2020-08-21 13:22:35","http://duxingxia.pro/mnooo/sites/ppxxayipeame/","offline","malware_download","doc|emotet|epoch2|heodo","duxingxia.pro","154.209.169.213","139880","HK" "2020-08-20 11:05:47","https://inwao.com/wp-admin/1838474119/544804/QMPCPPy/","offline","malware_download","doc|emotet|epoch3|Heodo","inwao.com","156.249.227.71","139880","SC" "2020-08-19 12:58:07","http://duxingxia.pro/mnooo/Overview/i4lddus39/p73992003136r1i7n3fc5sjyg89/","offline","malware_download","doc|emotet|epoch2|Heodo","duxingxia.pro","154.209.169.213","139880","HK" "2020-08-17 16:45:06","http://aqcszh.com/404/available-array/security-tvwkzw40cmwy-pfbzszrizmrw/9s8tgy5bh8umd7-5w6szw9/","offline","malware_download","doc|emotet|epoch1|heodo","aqcszh.com","156.253.46.70","139880","SC" "2020-08-12 11:07:11","http://zanxcx.com/wp-content/qwcrp7w/7py47472163887565275gg3596qdka/","offline","malware_download","doc|emotet|epoch2|heodo","zanxcx.com","154.209.164.164","139880","HK" "2020-07-22 13:00:11","https://www.wkkjf.com/wp-admin/589qi8k0/","offline","malware_download","doc|emotet|epoch2|heodo","www.wkkjf.com","156.227.98.179","139880","SC" "2020-06-10 20:02:35","http://sysnamiq.com/uohlcyy/uK/2N/0GN6V39K.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-06-10 19:54:38","http://sysnamiq.com/uohlcyy/dY/ak/IQDU6heX.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-06-10 19:44:18","http://sysnamiq.com/uohlcyy/LC/M8/u0fc8CKv.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-06-10 13:38:04","http://sysnamiq.com/vodzxx/W9/uL/JXZ5c6EC.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-06-10 13:24:12","http://sysnamiq.com/uohlcyy/Qa/qC/PUTVYCj0.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-06-10 12:05:30","http://sysnamiq.com/vodzxx/JA1opQjgjW.zip","offline","malware_download","Qakbot|Quakbot|zip","sysnamiq.com","154.215.105.248","139880","SC" "2020-02-05 22:02:08","http://jr921.cn/wp-admin/Documentation/pwajqa90rn/3og6542354tsr69t42o/","offline","malware_download","doc|emotet|epoch2|Heodo","jr921.cn","154.194.189.168","139880","SC" "2020-02-05 03:52:10","http://2285753542.com/87zkd3f/74g-ke-3382/","offline","malware_download","doc|emotet|epoch3|heodo","2285753542.com","154.206.141.162","139880","SC" "2020-02-03 18:44:14","https://www.xzdir.cn/wp-admin/esp/","offline","malware_download","doc|emotet|epoch2|heodo","www.xzdir.cn","154.206.183.179","139880","SC" "2020-02-01 00:32:14","http://2285753542.com/87zkd3f/DOC/xixu0zgff424/","offline","malware_download","doc|emotet|epoch2|heodo","2285753542.com","154.206.141.162","139880","SC" "2020-01-29 08:49:10","https://www.starhrs.com/blog/a14fo7w8jzxen_ixhr84zi1upt_996955114_vLYcByVLYfTm/security_portal/gmfte2pd7e4_vz1648770utt68/","offline","malware_download","doc|emotet|epoch1|Heodo","www.starhrs.com","156.253.34.26","139880","SC" "2020-01-29 03:48:06","http://fzpf.uni28.com/wp-includes/payment/n4xyi8/","offline","malware_download","doc|emotet|epoch2|heodo","fzpf.uni28.com","154.82.37.249","139880","US" "2020-01-29 02:09:18","http://2285753542.com/87zkd3f/invoice/","offline","malware_download","doc|emotet|epoch2|heodo","2285753542.com","154.206.141.162","139880","SC" "2020-01-24 14:59:15","http://2285753542.com/87zkd3f/DOC/7okaq2-84415-815019-idrz-oefmosv1q/","offline","malware_download","doc|emotet|epoch2|heodo","2285753542.com","154.206.141.162","139880","SC" "2020-01-22 01:58:06","https://www.starhrs.com/blog/browse/mqtl-332483277-574-7id2ba6c3a-g9hei73n/","offline","malware_download","doc|emotet|epoch2|heodo","www.starhrs.com","156.253.34.26","139880","SC" "2020-01-20 15:13:06","http://fzpf.uni28.com/wp-includes/sNzulE/","offline","malware_download","doc|emotet|epoch3|Heodo","fzpf.uni28.com","154.82.37.249","139880","US" "2020-01-18 05:36:06","https://www.bzhw.com.cn/lnkvjs235jdhsed/ud-ixlry-45/","offline","malware_download","doc|emotet|epoch3|Heodo","www.bzhw.com.cn","156.254.88.107","139880","HK" "2020-01-18 05:22:06","https://bzhw.com.cn/lnkvjs235jdhsed/paclm/8zcsprr/","offline","malware_download","doc|emotet|epoch2|Heodo","bzhw.com.cn","156.254.88.107","139880","HK" "2020-01-16 14:42:09","https://www.starhrs.com/blog/closed-disk/corporate-warehouse/fzv-5z5933/","offline","malware_download","doc|emotet|epoch1|Heodo","www.starhrs.com","156.253.34.26","139880","SC" "2020-01-14 14:29:08","https://www.starhrs.com/blog/40919547_9K5i11WlSSOKTWDl_module/263559351134_AMMrrTEEOV_portal/eMANT_sc8jMn52kJdes/","offline","malware_download","doc|emotet|epoch1|Heodo","www.starhrs.com","156.253.34.26","139880","SC" "2020-01-13 23:06:13","https://bzhw.com.cn/wp-admin/Documentation/kidtobhx/","offline","malware_download","doc|emotet|epoch2|heodo","bzhw.com.cn","156.254.88.107","139880","HK" "2020-01-13 16:49:40","https://www.bzhw.com.cn/wp-admin/HYUVNFAN2TH/934g704uoq/","offline","malware_download","doc|emotet|epoch2|heodo","www.bzhw.com.cn","156.254.88.107","139880","HK" "2019-12-18 08:42:11","http://srt.oacat.com/emedz/smnl-B29-5836/","offline","malware_download","doc|emotet|epoch3|heodo","srt.oacat.com","156.253.155.219","139880","SC" "2019-11-05 23:30:15","https://vip.maohuagong.com/nlx4q/ufq/","offline","malware_download","emotet|epoch2|exe|Heodo","vip.maohuagong.com","154.214.76.18","139880","SC" "2019-07-01 14:28:05","http://defujinrong.com/wp-content/themes/begin/inc/AP_Remittance_Advice_pdf.jar","offline","malware_download","jar|stealer","defujinrong.com","154.209.174.37","139880","HK" "2019-07-01 07:30:09","http://sscanlian.com/vendor/phpunit/phpunit/src/Util/PHP/AP_Remittance_Advice_pdf.jar","offline","malware_download","jar|stealer","sscanlian.com","154.215.76.4","139880","SC" "2019-05-27 20:44:08","http://cuijunxing.cn/wp-content/opuxfo4w52dxan_2kc3kikf7-121850386/","offline","malware_download","doc|emotet|epoch2","cuijunxing.cn","154.89.237.71","139880","SC" "2019-05-25 01:42:17","http://cuijunxing.cn/wp-content/FILE/XwwkhYgxtWKsAa/","offline","malware_download","doc|Emotet|Heodo","cuijunxing.cn","154.89.237.71","139880","SC" "2019-04-01 19:24:55","http://iqos.uni28.com/wp-admin/trust.accounts.resourses.biz/","offline","malware_download","","iqos.uni28.com","154.82.37.249","139880","US" "2019-03-29 22:39:08","https://youdaihe.com/wp-admin/S2s6/","offline","malware_download","emotet|epoch1|exe|Heodo","youdaihe.com","154.215.76.69","139880","SC" "2019-03-26 16:02:16","http://iqos.uni28.com/wp-admin/hf332t-d65ahzo-qisyqqv/","offline","malware_download","doc|emotet|epoch2|Heodo","iqos.uni28.com","154.82.37.249","139880","US" "2019-01-31 02:08:06","http://yulimaria.com/wp-content/uploads/LQoV-c8_KyX-iP/INVOICE/US_us/Document-needed/","offline","malware_download","emotet|epoch1|Heodo","yulimaria.com","154.82.52.46","139880","US" "2019-01-29 04:42:20","http://www.yulimaria.com/wp-content/uploads/LQoV-c8_KyX-iP/INVOICE/US_us/Document-needed/","offline","malware_download","doc|emotet|epoch1|Heodo|Quakbot","www.yulimaria.com","154.82.52.46","139880","US" "2019-01-25 19:38:08","http://www.yulimaria.com/wp-content/uploads/qFoh-Ax_QzXXBz-EZU/Invoice/2480086/US_us/Invoice-39198173-January/","offline","malware_download","doc|emotet|epoch2","www.yulimaria.com","154.82.52.46","139880","US" "2019-01-23 21:22:15","http://yulimaria.com/wp-content/uploads/Documents/01_19/","offline","malware_download","doc|emotet|epoch1|Heodo","yulimaria.com","154.82.52.46","139880","US" "2019-01-23 19:31:40","http://www.yulimaria.com/wp-content/uploads/Documents/01_19/","offline","malware_download","emotet|epoch1|Heodo","www.yulimaria.com","154.82.52.46","139880","US" "2018-11-19 19:49:34","http://hotellaspalmashmo.com/713SMBYOFRJ/biz/Commercial/","offline","malware_download","emotet|heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-10-06 15:11:04","http://hotellaspalmashmo.com/9bzK9EBuXD/","offline","malware_download","Emotet|exe|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-10-05 15:39:03","http://hotellaspalmashmo.com/9bzK9EBuXD","offline","malware_download","emotet|exe|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-10-04 08:16:23","http://hotellaspalmashmo.com/81MONDOJG/SWIFT/US","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-10-01 12:52:09","http://hotellaspalmashmo.com/sHQJxP2H97","offline","malware_download","emotet|exe|heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-09-24 21:24:10","http://hotellaspalmashmo.com/92WKNDMR/PAYMENT/Smallbusiness","offline","malware_download","doc|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-09-24 13:33:56","http://hotellaspalmashmo.com/713SMBYOFRJ/biz/Commercial","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-09-12 09:15:18","http://hotellaspalmashmo.com/AyBl","offline","malware_download","AgentTesla|emotet|exe|heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-09-11 05:13:00","http://politicasdocus.com/5ZOVMDRMM/SWIFT/Business/","offline","malware_download","doc|emotet|epoch2","politicasdocus.com","45.204.167.12","139880","SC" "2018-09-07 03:03:08","http://politicasdocus.com/5ZOVMDRMM/SWIFT/Business","offline","malware_download","doc|emotet|epoch2|Heodo","politicasdocus.com","45.204.167.12","139880","SC" "2018-09-06 18:59:04","http://hotellaspalmashmo.com/305102X/SWIFT/US/","offline","malware_download","doc|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-09-05 16:46:29","http://hotellaspalmashmo.com/305102X/SWIFT/US","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-24 08:29:12","http://hotellaspalmashmo.com/0YLLU/biz/Smallbusiness","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-21 14:41:55","http://hotellaspalmashmo.com/2928ZZYD/ACH/Smallbusiness","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-14 04:23:42","http://hotellaspalmashmo.com/sites/US/Open-invoices/INV12020918101383/","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-14 04:23:41","http://hotellaspalmashmo.com/924LCorporation/GN81509269331QF/Aug-08-2018-953844/QPSK-ZYLGD-Aug-08-2018/","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-13 15:59:42","http://hotellaspalmashmo.com/sites/US/Open-invoices/INV12020918101383","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-09 05:47:43","http://hotellaspalmashmo.com/924LCorporation/GN81509269331QF/Aug-08-2018-953844/QPSK-ZYLGD-Aug-08-2018","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-09 05:15:58","http://hotellaspalmashmo.com/DOC/XGM39404315038TSQFR/1264700381/WCZ-OQSW-Aug-06-2018/","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-08 05:49:51","http://hotellaspalmashmo.com/DOC/XGM39404315038TSQFR/1264700381/WCZ-OQSW-Aug-06-2018","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-08 05:07:01","http://sportleg.com/LLC/MCH548327SCR/Aug-07-2018-26279140/CP-ZPFM-Aug-07-2018/","offline","malware_download","doc|emotet|heodo","sportleg.com","154.194.137.182","139880","SC" "2018-08-07 15:02:22","http://sportleg.com/LLC/MCH548327SCR/Aug-07-2018-26279140/CP-ZPFM-Aug-07-2018","offline","malware_download","doc|emotet|Heodo","sportleg.com","154.194.137.182","139880","SC" "2018-08-03 05:16:56","http://hotellaspalmashmo.com/s7SG9ZMVoJRUnNz","offline","malware_download","doc|emotet|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-08-01 16:11:51","http://hotellaspalmashmo.com/s7SG9ZMVoJRUnNz/","offline","malware_download","doc|emotet|epoch2|Heodo","hotellaspalmashmo.com","156.254.40.24","139880","HK" "2018-07-11 00:47:22","http://www.chixg.com/newsletter/En_us/Client/Account-34989/","offline","malware_download","doc|emotet|epoch2|Heodo","www.chixg.com","154.199.37.102","139880","SC" "2018-07-03 16:19:05","http://chixg.com/hciyoer/U/","offline","malware_download","Emotet|Heodo","chixg.com","154.199.37.102","139880","SC" "2018-07-03 08:10:04","http://www.chixg.com/hciyoer/U/","offline","malware_download","emotet|exe|Heodo","www.chixg.com","154.199.37.102","139880","SC" "2018-07-03 05:47:23","http://chixg.com/ACCOUNT/Direct-Deposit-Notice/","offline","malware_download","emotet|heodo","chixg.com","154.199.37.102","139880","SC" "2018-07-02 16:27:44","http://www.chixg.com/ACCOUNT/Direct-Deposit-Notice/","offline","malware_download","doc|emotet|heodo","www.chixg.com","154.199.37.102","139880","SC" "2018-06-30 06:17:55","http://www.chixg.com/Client/INV2313159","offline","malware_download","emotet|heodo","www.chixg.com","154.199.37.102","139880","SC" "2018-06-30 06:02:46","http://chixg.com/FILE/Pay-Invoice","offline","malware_download","emotet|heodo","chixg.com","154.199.37.102","139880","SC" "2018-06-30 06:02:44","http://chixg.com/Client/INV2313159","offline","malware_download","emotet|heodo","chixg.com","154.199.37.102","139880","SC" "2018-06-29 04:44:26","http://www.chixg.com/Client/INV2313159/","offline","malware_download","emotet|heodo","www.chixg.com","154.199.37.102","139880","SC" "2018-06-28 19:03:05","http://chixg.com/Client/INV2313159/","offline","malware_download","Heodo","chixg.com","154.199.37.102","139880","SC" "2018-06-26 20:51:20","http://chixg.com/FILE/Pay-Invoice/","offline","malware_download","doc |emotet|epoch2|Heodo","chixg.com","154.199.37.102","139880","SC" "2018-06-22 16:33:04","http://atakentegitimkurumlari.com/INVOICE-STATUS/Payment/","offline","malware_download","doc|emotet|heodo","atakentegitimkurumlari.com","45.204.234.204","139880","SC" "2018-06-05 23:37:07","http://www.hanokj.com/rv91c/","offline","malware_download","emotet|Heodo|payload","www.hanokj.com","154.214.65.155","139880","SC" "2018-06-05 11:00:01","http://violet-eg.com/olupa.exe","offline","malware_download","AgentTesla|eldorado|exe","violet-eg.com","154.206.164.19","139880","SC" "2018-06-04 22:49:54","http://violet-eg.com/hus/yaya.exe","offline","malware_download","downloader|exe","violet-eg.com","154.206.164.19","139880","SC" "2018-06-04 18:15:44","http://violet-eg.com/hus/yaski.exe","offline","malware_download","exe","violet-eg.com","154.206.164.19","139880","SC" "2018-06-04 16:47:57","http://violet-eg.com/hus/egbon.exe","offline","malware_download","AgentTesla|downloader|exe","violet-eg.com","154.206.164.19","139880","SC" "2018-06-04 16:46:16","http://violet-eg.com/hus/olu.exe","offline","malware_download","downloader|exe","violet-eg.com","154.206.164.19","139880","SC" "2018-05-28 07:03:06","http://prokeyboardist.com/cciXI/","offline","malware_download","Emotet|exe|Heodo","prokeyboardist.com","156.254.49.111","139880","HK" "2018-05-17 18:53:16","http://prokeyboardist.com/0qLVjK7JgMX/","offline","malware_download","doc|emotet|Heodo","prokeyboardist.com","156.254.49.111","139880","HK" "2018-05-16 16:58:53","http://www.3v5.net/images/162b671160d12c3baef99fece8c1bfdb.zip","offline","malware_download","downloader|zip","www.3v5.net","156.254.42.76","139880","HK" "2018-03-09 12:29:44","http://dichvusonnha.com/templates/tp-template/html/com_content/archive/tmpl/invoice_201711_419372.exe","offline","malware_download","exe|Ransomware","dichvusonnha.com","154.206.163.49","139880","SC" # of entries: 104