URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host

Database Entry

Spamhaus DBL:Unknown
SURBL:Not listed
Firstseen:2018-03-28 11:22:07 UTC

IP addresses

The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-04-16 06:56:1731.220.40.22nl7.nlkoddos.comNot listedAS206264 AMARUTU-TECHNOLOGY- DEyes

Malware URLs

The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2018-07-10 06:36:07http:// Loki Phishing@abuse_ch
2018-07-06 12:43:04http:// Fuery Loki Phishing@oppimaniac
2018-07-06 09:38:02http:// downloader RTF Phishing@oppimaniac
2018-07-06 09:38:02http:// Phishing@oppimaniac
2018-06-27 11:43:16http:// Loki Phishing@abuse_ch
2018-06-23 15:06:02http://
2018-06-02 15:59:11http://
2018-05-30 13:44:25http:// Loki Phishing@abuse_ch
2018-05-24 19:15:20http:// Loki Phishing@abuse_ch
2018-05-24 13:18:26http:// Phishing@abuse_ch
2018-05-20 16:44:23http:// exe Loki Phishing@lovemalware
2018-05-17 22:47:52http:// Formbook Pony Phishing@lovemalware
2018-05-16 22:46:34http:// exe Loki Phishing@lovemalware
2018-05-15 23:01:18http:// exe Loki Phishing@lovemalware
2018-05-12 11:41:46http:// Loki Phishing@abuse_ch
2018-03-28 11:22:12http:// macro powershell downloader doc md5:4598e545ec0e6edf46564d4f1e645ced md5:ca9853eda6441f5eb880e94dcd83be2c Phishing@c_APT_ure