URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: amautatravel.com
Domain registrar:NameSilo -
Domain registration date:2019-06-28 19:27:33 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-18 10:40:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-17 13:45:22 195.250.27.46s3450.mex1.stableserver.netNot listedAS211126 WHG-MEX- MXyes
2023-06-28 09:32:21 91.195.240.12Not listedAS47846 SEDO-AS- DEno
2025-05-08 15:20:22 195.250.27.44s3448.mex1.stableserver.netNot listedAS211126 WHG-MEX- MXno
2025-04-28 03:35:15 195.250.27.29s3417.mex1.stableserver.netNot listedAS211126 WHG-MEX- MXno
2023-05-25 01:32:50 92.38.150.180s685.gru5.mysecurecloudhost.comNot listedAS199524 GCORE- BRno
2023-02-11 11:45:31 185.151.30.195185-151-30-195.ptr4.stackcp.netNot listedAS48254 TWENTYI- GBno
2022-05-20 02:46:49 148.163.69.161.Not listedAS53755 IOFLOOD- USno
2022-03-18 10:40:07 148.163.69.135usvip2.noc84.comNot listedAS53755 IOFLOOD- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-18 13:34:06http://amautatravel.com/cgi-bin/WhWIic/Offlinedll emotet ext epoch4 heodo ext Cryptolaemus1
2022-03-18 10:40:07https://amautatravel.com/cgi-bin/WhWIic/Offlinedll emotet ext epoch4 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-18 20:34:28103f6f0d180ee9dc918237d79ecd84638ec3969a8e709bade6e6a9e6d99e87abdll Heodo
2022-03-18 20:30:58103f6f0d180ee9dc918237d79ecd84638ec3969a8e709bade6e6a9e6d99e87abdll Heodo
2022-03-18 20:00:391675cd491cfac19ad6a45ad4fd3565d45c888a13fe0c84ae298808aa8b44df62dll Heodo
2022-03-18 19:53:49407d06ffe7dc997a77b1d1d9fed6e6ace8c10c10168c38e4ba6d37fc94fde5c4dll Heodo
2022-03-18 19:19:56b53fa38f24092d3523f53c13485ca0d03fbfeb5929c6f6c20a8087de4b90e174dll Heodo
2022-03-18 19:17:47b2e065d1d609d4e3f5f9407e9c71495eed8852e5210e8a682825273bbaf18b7cdll Heodo
2022-03-18 18:53:31c075475fb539f1a1b4ab836d68a37b7c403f659974ff52efc1077e803c97de46dll Heodo
2022-03-18 18:33:34e0123774ba07aea3d5e3d4930e212f37693130c420006964b63ee048476caa79dll Heodo
2022-03-18 18:22:4574b6342b08e13fc019d5db0ffe4f23804814dd483441b996cf25de31de23e7d8dll Heodo
2022-03-18 18:13:430f2df867b8fa85c1a5f89c45752be889cf6f890b70166b63b0aa47f526b54825dll Heodo
2022-03-18 17:59:34abe13cd7c4068fd758063ab23fbdcf8a9bf1f6f4f9441642a9dcfb786c8bfd12dll Heodo
2022-03-18 17:40:39c76dba138d762bd2300cd92a85642554f3f4b02710b7f35d9fe526a30a96ee1bdll Heodo
2022-03-18 17:18:454b53265e4261c7128d1dd6e9ef8036bb6acc40035c7d37884932eed9cfed9029dll Heodo
2022-03-18 17:13:483dea2e6afa4382d285a904f22317ddba33cd4b0e76d5d23d3d852da4b633bb46dll Heodo
2022-03-18 16:58:405b59d5891e381efd72415555a42b1196ef755d70ff66b830e1ecbcd807cad737dll Heodo
2022-03-18 16:56:225b59d5891e381efd72415555a42b1196ef755d70ff66b830e1ecbcd807cad737dll Heodo
2022-03-18 16:24:5103d79294bfde1d3c3c7d9a220049e1873234483335fe08803cababa351c42ef1dll Heodo
2022-03-18 16:22:2903d79294bfde1d3c3c7d9a220049e1873234483335fe08803cababa351c42ef1dll Heodo
2022-03-18 15:52:46301c112f9581b3e5a935edc3dadc9e4c7f1792b1245376d0e30ebe64fec33bbbdllHeodo
2022-03-18 15:39:26b4e57f1d2dbc600b5691fc4b98385706e77513f6fd7c1c4b6f3a9719f487cca2dll Heodo
2022-03-18 15:17:56ea58943995669c4a6d3067fdb8d778320c6d792c2b2dad0a3b8009e44cce85ffdll Heodo
2022-03-18 15:02:315e1efa0f6c716fc6c7cad4caa0daae9e98a21a1b90c96e2a1e6cb6c3f97250c5dllHeodo
2022-03-18 14:34:415032eee2b365492c21c3b78fa3b18c681cbd451bc6e9e415f109f3a009bca8b7dll Heodo
2022-03-18 14:33:545032eee2b365492c21c3b78fa3b18c681cbd451bc6e9e415f109f3a009bca8b7dll Heodo
2022-03-18 14:22:45d76010ad33b6e41c750c1d95273e5d6330d9b2c07e2b7bcbb9630f1eaa95f4d5dll Heodo
2022-03-18 14:14:49ce759b924d7e320c2d7f2846f74a3da97ebefa02c49509918c012e08903ee009dllHeodo
2022-03-18 13:36:0352f950a6c3f740224185a57346044df7bd0cb3d43a6eb2e5f151d5dd9a93a231dll Heodo
2022-03-18 13:34:05e5b6c06389099b8f35de001e0e481c9afd12f3e1e8107f57079d5e32f87f2d56dll Heodo
2022-03-18 13:03:4599f7ab59e661b2c930f78ca16694ff9b79f3ee0ee377f765d7a75715af1931cadll Heodo
2022-03-18 12:34:42112c33df42d3d43aa149ba94a1cb4485e88e1361d9b6c80eabf9a929c0dfe3a3dll Heodo
2022-03-18 11:54:59d303983f013d721e360c85bcefbeef762f3deeecc416c26570dabe2b95ab07cadll Heodo
2022-03-18 11:33:079a9f108b1a8d3189527b4167ba1fb8508320ffb3e968cc01ffba81a0d001afdddll Heodo
2022-03-18 10:57:032e02733830d79de188144e8bcd2dee36009a86519a763d8f9299d1815bc7eb1bdll Heodo
2022-03-18 10:40:071f09cad84e44fcc4628a8c84bdd95d5bd4c2999d1451b09ebac27ffe0e183b12dll Heodo