URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 33x.us
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-07-20 19:52:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-05 13:42:22 111.92.243.170Not listedAS401696 COGNETCLOUD- HKyes
2025-09-26 22:29:31 47.86.19.19Not listedAS45102 ALIBABA-CN-NET- HKno
2025-07-27 05:55:23 154.222.19.95Not listedAS401696 COGNETCLOUD- SCno
2025-07-25 12:31:12 154.222.19.96Not listedAS401696 COGNETCLOUD- SCno
2025-06-19 05:29:55 154.217.242.6Not listedAS400619 AROSS-AS- SCno
2025-04-30 05:00:25 111.92.243.204Not listedAS401696 COGNETCLOUD- HKno
2020-08-25 06:29:18 18.213.250.117ec2-18-213-250-117.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2020-08-25 06:29:18 18.215.128.143ec2-18-215-128-143.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2020-08-25 06:29:18 52.4.209.250ec2-52-4-209-250.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2020-07-20 19:52:11 119.28.226.73Not listedAS132203 TENCENT-NET-AP-CN- HKno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-21 05:13:38http://33x.us/wp-admin/personal_zone/open_profi...Offlinedoc emotet ext epoch1 Cryptolaemus1
2020-07-20 19:52:11https://33x.us/wp-admin/personal_zone/open_prof...Offlinedoc emotet ext epoch1 heodo ext ZLoader ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-21 00:49:073972a355c99ea89052d74c11fef216d419a29acf9958bc15a3c8b6aab1e2853adoc Heodo
2020-07-21 00:37:3549b857e2068f710d1facd444264c6d8804ecc9e2ba9660953b24bbf213cc66badoc Heodo
2020-07-21 00:23:1833e64096db5340fb26c5b5d6f9b1dd89674d3a77a96a25fafcb878d9929fc9dadoc Heodo
2020-07-21 00:10:401e585df85081a824f1ec5c3f6a51599addb89b03a63bc0a5883c5f9c2d877187doc Heodo
2020-07-21 00:01:47cce8e5e706869261ede523822b673dd52e48d4351de8600f5ac209a7f0189629docHeodo
2020-07-20 23:54:280d657d365282571dcf58adbb3a758c81fa3df50bc081a60d01f14c5431b9492edoc  
2020-07-20 23:37:49518def77204a86e55289809beda7c491b0f9ab290b10d7b4bae1c670a0f69c8ddoc Heodo
2020-07-20 23:22:1168f85e639cf07fc84c8204cec1bd82fd8985d854aa17d02c89b58b255b98ed48doc  
2020-07-20 23:02:52a6ca24bb5b1de30cd63ecceac1727ca4102ed289d65fa05c550c4485e6ca372bdoc  
2020-07-20 22:48:33c0696d196c346305861f4e358f48f216dcdde4251309abed3547504007cb858cdoc  
2020-07-20 22:43:07616dde6dc6e22e28f4149e26996578dde114b40f896cee3cb36165d52ff70857doc  
2020-07-20 22:31:061269bdbbc40be92cc1f13918a692b34fdfeec466bd7d872863ecc405ff38f77fdoc ZLoader
2020-07-20 22:18:17c6050ddd07c6d8c4aee73c52d0e50d6056ebd5f3e82550d8c771fc4353d489fedoc  
2020-07-20 22:05:23c5dc7db865c477ba217342107932a67cab54659a8a870fa16a9d2f21ec3aade2doc  
2020-07-20 21:54:4600593b1d3ba64e5ca39e6c503ab0f33dcade0d3afb65c2a73f2d4696cf8a7bb0doc ZLoader
2020-07-20 21:42:13d28f9dea8c5837be7474d3735799da462ae74c0a0f3e7279a3eb8a50ba6183eedoc  
2020-07-20 21:30:1810e15c8850925b8f03210b06fdc2e0e87bd7339bf6a185992346e2063cbe1e99doc  
2020-07-20 21:17:32f4295c97af0389a32cb42495d1b102a8e8698e5f107c50034cee1d0ef8735a1adoc  
2020-07-20 21:12:15b431233adfd3e63e12727df15f9fd91134c9e87b1e69f570a87bc8b04561b060doc  
2020-07-20 21:00:17d06b767d98bec7fa338114b2e77b1db8b1a8962819fda91258575e6cc7910b31doc  
2020-07-20 20:41:287812b414ab8098b436f22af0523a1edb14b8af7eb4df4bac66f9268cdb074e96doc  
2020-07-20 20:29:0897e66ad16955f21f83dae53917dbdefba08fc07108392a96327eeef55698a04cdoc  
2020-07-20 20:15:23dc83903be08352444bfd3116d33bda30da619c60371f037e0bd56f82a2a768fbdoc Heodo
2020-07-20 20:09:22ed29b479d20901bb285c8146d9a69a73a34eadaa4f6c86aca69aeefe96f4fe0fdoc  
2020-07-20 19:52:116fe64c172aacbb720a04102b199a92ed159ba37fd83bb41cc2db48e55237985edoc