URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: aeginc.co
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-04-25 22:31:01 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-06 00:18:26 5.223.54.221node20.cloudrambo.comNot listedAS215859 HETZNER-CLOUD4-AS- SGyes
2025-05-04 13:56:12 147.50.231.34sv1.angahosting.comNot listedAS9891 CSLOX-IDC-AS-AP- THno
2019-07-12 06:31:55 103.86.48.22hostings.ruk-com.in.thNot listedAS58955 BANGMODENTERPRISE-TH- THno
2019-04-25 22:31:05 45.77.37.20445.77.37.204.vultrusercontent.comNot listedAS20473 AS-VULTR- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-25 22:31:05https://aeginc.co/wp-includes/Scan/OyZ8E1Bt/Offlineemotet ext heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-26 02:23:178065d2137332893c6e189b09a0e6b480e2f2955e827e0b67e4418e6a268da467doc Heodo
2019-04-26 01:37:1700a73162489f59b1cc4fc07208676176c19eadbe5c4c0f16b0bd3f7c15a9a03adoc Heodo
2019-04-26 00:58:1379aa4c12cd7acda388199e7e59ac3481b7e738ae2b3a43ac06bf08dd8f6b4419doc Heodo
2019-04-25 23:24:18828b7e9914f932108e52249577fa80987f20ebda94b8654fdc2964baa4d929a4doc Heodo
2019-04-25 22:31:0467d05dd367015c892e3f0f50e5737a5138f00f626a134a85f1c2a6496132e691doc