URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: alibabamakemerich.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-16 20:46:03 UTC
Total malware sites :1
A record(s) observed :41

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-06 02:02:57 185.107.56.208Not listedAS43350 NFORCE- NLyes
2025-11-02 08:13:10 82.192.80.79Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2025-10-08 18:11:20 185.107.56.210Not listedAS43350 NFORCE- NLno
2025-11-01 01:15:05 82.192.80.80Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2025-10-14 20:55:15 185.107.56.207Not listedAS43350 NFORCE- NLno
2025-08-18 06:56:38 77.247.179.91Not listedAS43350 NFORCE- NLno
2025-05-25 07:54:57 77.247.179.90Not listedAS43350 NFORCE- NLno
2025-10-12 10:31:51 185.150.189.123emails.victorkaiser.comNot listedAS23470 RELIABLESITE- USno
2025-10-03 10:47:40 185.150.189.166ny-117.vshield.proNot listedAS23470 RELIABLESITE- USno
2025-06-04 10:39:39 77.247.179.87Not listedAS43350 NFORCE- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-16 20:46:04http://alibabamakemerich.com/wp-includes/esp/ed...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-18 02:25:02360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134docHeodo
2020-10-16 20:46:0400ca7ef024a663527f5295900154321d98f6422070bbdf2c9c2abe268370b811docHeodo