############################################################################## # URLhaus ASN CSV Feed # # Generated on 2025-11-20 02:23:35 UTC # # # # For questions please refer to: # # https://urlhaus.abuse.ch/feeds/ # ############################################################################## # # Feed generated for AS20738 # # Dateadded (UTC),URL,URL_status,Threat,Tags,Host,IPaddress,ASnumber,Country "2024-05-22 16:06:09","https://laurabingham.org/wp-content/plugins/wp-recipe-maker/downexcel.php","offline","malware_download","64|DarkGate|exe","laurabingham.org","46.32.254.216","20738","GB" "2023-05-17 13:06:34","https://freesiahealth.com/idc/?1","offline","malware_download","BB28|geofenced|js|Qakbot|Quakbot|USA","freesiahealth.com","212.48.68.14","20738","GB" "2023-05-03 19:45:13","http://totalassist.co.uk/gnome2/rentfree.zip","offline","malware_download","geofenced|obama260|Qakbot|Qbot|Quakbot|USA|wsf|zip","totalassist.co.uk","46.32.255.172","20738","GB" "2023-04-12 18:44:47","http://totalassist.co.uk/uiia/autemet.php","offline","malware_download","921|BB23|geofenced|Qakbot|Qbot|Quakbot|tr|USA|wsf|zip","totalassist.co.uk","46.32.255.172","20738","GB" "2022-11-02 01:56:45","https://justlearncharity.org.uk/roei/qbot.zip","offline","malware_download","BB05|BV1|iso|qakbot|qbot|quakbot|TR|zip","justlearncharity.org.uk","94.136.40.51","20738","GB" "2022-01-20 15:27:04","https://betablog.summertowndental.co.uk/i4x38z/0eH5CC82TXFnK/","offline","malware_download","emotet|epoch4|redir-doc|xls","betablog.summertowndental.co.uk","46.32.230.88","20738","GB" "2022-01-20 15:27:04","https://betablog.summertowndental.co.uk/i4x38z/0eH5CC82TXFnK/?i=1","offline","malware_download","doc|emotet|epoch4|Heodo|SilentBuilder","betablog.summertowndental.co.uk","46.32.230.88","20738","GB" "2022-01-19 21:05:04","https://betablog.summertowndental.co.uk/i4x38z/9l0/","offline","malware_download","emotet|epoch4|redir-doc","betablog.summertowndental.co.uk","46.32.230.88","20738","GB" "2022-01-19 21:05:04","https://betablog.summertowndental.co.uk/i4x38z/9l0/?i=1","offline","malware_download","doc|emotet|epoch4|Heodo|SilentBuilder","betablog.summertowndental.co.uk","46.32.230.88","20738","GB" "2021-12-23 21:37:06","http://eurofit-ni.com/wp-content/ByjXVc1CkxPemDh/","offline","malware_download","emotet|epoch4|redir-doc|xls","eurofit-ni.com","79.170.44.131","20738","GB" "2021-06-29 07:11:04","http://morningstarlincoln.co.uk/site/bmx/estudiante.exe","offline","malware_download","exe|RedLineStealer","morningstarlincoln.co.uk","79.170.44.146","20738","GB" "2021-04-20 13:19:04","http://ehs.co.zw/veron/fad/Wj7R1Fd4luz1nGs.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:15:04","http://ehs.co.zw/veron/dj/O73jpH5gC4FjsrZ.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:14:33","http://ehs.co.zw/veron/ef/j6lPAi8ei08vYtt.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:14:21","http://ehs.co.zw/veron/ok/lrrDXT9Ki8uX1AU.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:14:06","http://ehs.co.zw/veron/bo/OuhG2j4d9cP8mkZ.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:14:04","http://ehs.co.zw/veron/dec/V7xj0esEUgFxjyl.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 13:14:04","http://ehs.co.zw/veron/ja/dJmxBVmgOdaTg5G.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-20 12:17:04","http://ehs.co.zw/veron/sik/FOFpJL1H68YigMz.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2021-04-16 15:00:05","http://ehs.co.zw/abobi/isur/INVOICE.exe","offline","malware_download","AgentTesla|exe","ehs.co.zw","176.32.230.50","20738","GB" "2020-10-20 19:56:03","https://edwardscontracting.co.uk/test/eTrac/lzacd749jvdo/yhw8w2/","offline","malware_download","doc|emotet|epoch2|Heodo","edwardscontracting.co.uk","176.32.230.13","20738","GB" "2020-09-02 08:09:23","http://www.hygienicwallcladding.com/ucbucwmtfkan/555555555.png","offline","malware_download","AnyDesk|DEU|Emotet|geofenced|Heodo|Qakbot|qbot|Quakbot|spx164","www.hygienicwallcladding.com","79.170.40.54","20738","GB" "2020-08-20 13:22:05","http://flexitravel.com/spo3lart/deeb9ufyln/","offline","malware_download","doc|emotet|epoch2|heodo","flexitravel.com","176.32.230.44","20738","GB" "2020-08-13 16:12:04","http://flexitravel.com/5kw6197/swift/","offline","malware_download","doc|emotet|epoch2|heodo","flexitravel.com","176.32.230.44","20738","GB" "2020-08-12 22:05:18","http://altdigital.co.uk/js/tCmXt/","offline","malware_download","emotet|epoch1|exe|heodo","altdigital.co.uk","94.136.40.82","20738","GB" "2020-08-07 10:52:11","http://flexitravel.com/XVXcoxDGs/","offline","malware_download","doc|emotet|epoch3|Heodo|QuakBot","flexitravel.com","176.32.230.44","20738","GB" "2020-07-30 14:19:07","http://altdigital.co.uk/js/private-module/verified-profile/myoigsxqpsim-0z8u685t/","offline","malware_download","doc|emotet|epoch1|Heodo","altdigital.co.uk","94.136.40.82","20738","GB" "2020-07-28 10:56:34","http://flexitravel.com/gzb13pe4u50/po70838682154135sp2k9w5wkjly8b/","offline","malware_download","doc|emotet|epoch2|Heodo","flexitravel.com","176.32.230.44","20738","GB" "2020-06-05 13:44:29","http://planelocations.com/dagllf/Y/cSF228Gqu.zip","offline","malware_download","Qakbot|Quakbot|zip","planelocations.com","79.170.40.236","20738","GB" "2020-06-02 15:35:12","http://oknepal.com.np/sjuwvnyrkbbp/NQAD_62238627_01062020.zip","offline","malware_download","Qakbot|qbot|spx131|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-06-02 15:35:07","http://oknepal.com.np/sjuwvnyrkbbp/NQAD_173637_01062020.zip","offline","malware_download","Qakbot|qbot|spx131|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-06-02 15:35:03","http://oknepal.com.np/sjuwvnyrkbbp/9847/NQAD_9847_01062020.zip","offline","malware_download","Qakbot|qbot|spx131|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-06-02 09:42:44","http://planelocations.com/gkyzjvecu/NQAD_899260_01062020.zip","offline","malware_download","Qakbot|Quakbot|zip","planelocations.com","79.170.40.236","20738","GB" "2020-06-02 09:39:12","http://planelocations.com/gkyzjvecu/6714/NQAD_6714_01062020.zip","offline","malware_download","Qakbot","planelocations.com","79.170.40.236","20738","GB" "2020-06-02 07:24:52","http://oknepal.com.np/sjuwvnyrkbbp/42661/NQAD_42661_01062020.zip","offline","malware_download","Qakbot|Quakbot|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-06-02 06:57:28","http://oknepal.com.np/sjuwvnyrkbbp/98024968/NQAD_98024968_01062020.zip","offline","malware_download","Qakbot|Quakbot|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-06-02 06:33:23","http://oknepal.com.np/sjuwvnyrkbbp/096099/NQAD_096099_01062020.zip","offline","malware_download","Qakbot|Quakbot|zip","oknepal.com.np","79.170.44.87","20738","GB" "2020-05-25 13:48:16","http://one2onedriving.co.uk/zxzhmxut/8888888.png","offline","malware_download","exe|Qakbot|Quakbot|spx126","one2onedriving.co.uk","79.170.40.38","20738","GB" "2020-05-06 16:49:09","http://www.theabigailbloomcakecompany.co.uk/wp-content/uploads/2020/05/tlclp/30344/EmploymentVerification_30344_05052020.zip","offline","malware_download","Qakbot|qbot|spx114|zip","www.theabigailbloomcakecompany.co.uk","79.170.40.4","20738","GB" "2020-05-06 14:55:09","http://www.theabigailbloomcakecompany.co.uk/wp-content/uploads/2020/05/tlclp/EmploymentVerification_5062988_05052020.zip","offline","malware_download","Qakbot|qbot|spx114|zip","www.theabigailbloomcakecompany.co.uk","79.170.40.4","20738","GB" "2020-04-06 17:43:11","https://www.professionaldevelopmentpeople.com/wp-content/plugins/407/PAYMENT_119091031_CA.jar","offline","malware_download","jar","www.professionaldevelopmentpeople.com","212.48.70.142","20738","GB" "2020-02-25 12:31:03","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/dede.exe","offline","malware_download","agenttesla","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-25 12:28:06","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/kc.exe","offline","malware_download","agenttesla","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-25 12:28:04","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/chib.exe","offline","malware_download","agenttesla","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-25 12:28:02","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/whe.exe","offline","malware_download","Agenttesla","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-25 12:27:03","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/bnt.exe","offline","malware_download","AgentTesla","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-25 08:03:04","http://www.silverduckdesigns.co.uk/wp-content/uploads/2019/04/jiz.exe","offline","malware_download","AgentTesla|exe","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-24 17:55:13","http://silverduckdesigns.co.uk/wp-content/uploads/2018/07/chib.exe","offline","malware_download","AgentTesla|exe","silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-24 14:53:03","http://silverduckdesigns.co.uk/wp-content/uploads/2018/07/elb.exe","offline","malware_download","exe","silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2020-02-24 13:11:15","http://www.silverduckdesigns.co.uk/wp-content/uploads/2018/07/frr.exe","offline","malware_download","AgentTesla|exe","www.silverduckdesigns.co.uk","217.199.187.71","20738","GB" "2019-05-29 18:14:02","http://mattshortland.com/ozXYuMOiYlguFF/FILE/4ffkoq818anu8bt6_p5k9z-08161156/","offline","malware_download","doc|Emotet|epoch2|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-05-20 21:08:03","http://mattshortland.com/ozXYuMOiYlguFF/","offline","malware_download","doc|Emotet|epoch2|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-29 22:57:06","http://mattshortland.com/OLDSITE/trust.myaccount.resourses.biz/","offline","malware_download","doc|emotet|epoch1|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-26 23:31:03","http://mattshortland.com/OLDSITE/DoSq-7gWLH1kCyOajYaY_hvhAfrOXD-LL/","offline","malware_download","doc|emotet|epoch1","mattshortland.com","46.32.232.140","20738","GB" "2019-04-23 08:10:10","http://mattshortland.com/OLDSITE/service/Nachprufung/04-2019/","offline","malware_download","doc|emotet|epoch1|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-18 17:43:02","http://mattshortland.com/OLDSITE/DOC/apQ1RHpLZ/","offline","malware_download","","mattshortland.com","46.32.232.140","20738","GB" "2019-04-16 06:53:02","http://mattshortland.com/OLDSITE/ol1xe-xuy4wm-osqouvo/","offline","malware_download","doc|emotet|epoch2|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-11 06:01:03","http://mattshortland.com/OLDSITE/ksbn-zhmf4-hhvewc/","offline","malware_download","doc|emotet|epoch2|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-09 05:37:10","http://mattshortland.com/OLDSITE/k4msol-x6kzj-ovvts/","offline","malware_download","Emotet|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-04-05 22:49:28","http://mattshortland.com/OLDSITE/aSGB-XhqwGfUPWVDLwU_CFkjyaxeG-DhR/","offline","malware_download","Emotet|Heodo","mattshortland.com","46.32.232.140","20738","GB" "2019-03-11 23:26:02","http://46.32.231.239/wuxi2sx/r6qp-m7hpu-kzwe/","offline","malware_download","doc|emotet|epoch2|Heodo","46.32.231.239","46.32.231.239","20738","GB" "2019-03-05 16:23:19","http://46.32.231.239/PHPMailer_v5.1/1k1/","offline","malware_download","emotet|epoch2|exe|Heodo","46.32.231.239","46.32.231.239","20738","GB" "2019-02-14 12:11:09","http://www.emmawitter.co.uk/document/Receipt_Notice/DcFY-7KB_YQBHE-WM/","offline","malware_download","doc|emotet|epoch1|Heodo","www.emmawitter.co.uk","79.170.40.230","20738","GB" "2019-02-13 06:31:06","http://senital.co.uk/templates/a4joomla-ocean-free/js/messg.jpg","offline","malware_download","compressed|exe|javascript|payload|ransomware|stage1|stage2|TrolDesh|zip","senital.co.uk","79.170.40.33","20738","GB" "2019-02-08 11:36:02","http://www.professionaldevelopmentpeople.com/US/Copy_Invoice/2929115183204/fEOU-Eoiwi_E-HE/","offline","malware_download","Emotet|Heodo","www.professionaldevelopmentpeople.com","212.48.70.142","20738","GB" "2019-01-31 11:46:03","http://gsscomputers.co.uk/templates/a4joomla/js/massg.jpg","offline","malware_download","exe|Troldesh","gsscomputers.co.uk","79.170.40.32","20738","GB" "2019-01-29 22:15:10","http://jonathandocksey.co.uk/bQhkz_TW-HL/GU/Clients_Messages/2019-01/","offline","malware_download","emotet|epoch1|Heodo|Quakbot","jonathandocksey.co.uk","94.136.40.51","20738","GB" "2018-12-28 07:12:04","http://labphon15.labphon.org/modules/contextual/contextual.exe","offline","malware_download","exe","labphon15.labphon.org","217.199.187.63","20738","GB" "2018-12-05 06:28:02","http://candbs.co.uk/INFO/En_us/Invoice-6731448-December/","offline","malware_download","doc|emotet|epoch2|Heodo","candbs.co.uk","46.32.253.178","20738","GB" "2018-12-04 14:28:14","http://candbs.co.uk/INFO/En_us/Invoice-6731448-December","offline","malware_download","doc|emotet|heodo","candbs.co.uk","46.32.253.178","20738","GB" "2018-11-19 19:53:39","http://locksplus.co.uk/DOC/En_us/Past-Due-Invoices/","offline","malware_download","emotet|heodo","locksplus.co.uk","176.32.230.12","20738","GB" "2018-10-03 18:43:57","http://locksplus.co.uk/DOC/En_us/Past-Due-Invoices","offline","malware_download","doc|emotet|heodo","locksplus.co.uk","176.32.230.12","20738","GB" "2018-09-28 19:19:03","http://locksplus.co.uk/En_us/Transaction_details/09_18/","offline","malware_download","doc|Heodo","locksplus.co.uk","176.32.230.12","20738","GB" "2018-09-28 19:07:03","http://locksplus.co.uk/En_us/Transaction_details/09_18","offline","malware_download","doc|emotet|Heodo","locksplus.co.uk","176.32.230.12","20738","GB" "2018-09-18 18:16:05","http://flexitravel.com/23GGTALTK/biz/Commercial/","offline","malware_download","doc|Heodo","flexitravel.com","176.32.230.44","20738","GB" "2018-09-18 07:31:07","http://flexitravel.com/files/En_us/Past-Due-Invoices/","offline","malware_download","doc|Heodo","flexitravel.com","176.32.230.44","20738","GB" "2018-09-18 06:23:28","http://flexitravel.com/files/En_us/Past-Due-Invoices","offline","malware_download","doc|emotet|heodo","flexitravel.com","176.32.230.44","20738","GB" "2018-09-12 02:08:07","http://candbs.co.uk/47612GEIMJ/biz/US/","offline","malware_download","doc|emotet|epoch2|Heodo","candbs.co.uk","46.32.253.178","20738","GB" "2018-09-11 23:01:48","http://candbs.co.uk/47612GEIMJ/biz/US","offline","malware_download","doc|emotet|epoch2|Heodo","candbs.co.uk","46.32.253.178","20738","GB" "2018-09-06 03:15:17","http://hvacmantenimiento.com/81OQT/WIRE/Smallbusiness/","offline","malware_download","doc|emotet|epoch2","hvacmantenimiento.com","79.170.40.161","20738","GB" "2018-09-05 04:59:04","http://hvacmantenimiento.com/81OQT/WIRE/Smallbusiness","offline","malware_download","doc|emotet|epoch2|Heodo","hvacmantenimiento.com","79.170.40.161","20738","GB" "2018-08-02 03:32:47","http://podpea.co.uk/Tracking/US_us/","offline","malware_download","doc|emotet|epoch2|Heodo","podpea.co.uk","94.136.40.103","20738","GB" "2018-07-30 19:13:05","http://podpea.co.uk/DHL/US_us/","offline","malware_download","doc|emotet|epoch2|Heodo","podpea.co.uk","94.136.40.103","20738","GB" "2018-05-29 07:10:36","http://podpea.co.uk/Zahlung/Hilfestellung-zu-Ihrer-Rechnung-Nr00593/","offline","malware_download","doc|emotet","podpea.co.uk","94.136.40.103","20738","GB" "2018-05-23 14:56:18","http://podpea.co.uk/2DLIE6/","offline","malware_download","emotet|Heodo","podpea.co.uk","94.136.40.103","20738","GB" "2018-05-14 15:54:45","http://x717.com/update.php","offline","malware_download","AgentTesla|gandcrab|ransomware|Ransomware.GandCrab","x717.com","79.170.40.182","20738","GB" "2018-04-04 11:01:40","http://4rt.co.uk/INV/PEH-5974201397/","offline","malware_download","doc|emotet|heodo","4rt.co.uk","94.136.40.82","20738","GB" "2018-03-29 07:26:07","http://juliemadison.com/thlebct.exe","offline","malware_download","exe|retefe","juliemadison.com","217.199.164.1","20738","GB" "2018-03-13 09:24:15","http://juliemadison.com/wbckspp.exe","offline","malware_download","exe|Retefe","juliemadison.com","217.199.164.1","20738","GB" # of entries: 89