URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: amcoitsystems.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-14 05:26:02 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-17 18:35:24 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-09-17 18:35:24 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2020-08-14 05:26:04 172.67.209.105Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.112.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.16.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.32.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.48.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.64.1Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.80.1SBL681411AS13335 CLOUDFLARENETn/ano
2025-04-28 05:03:37 104.21.96.1Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-25 06:23:03http://amcoitsystems.com/wp/public/9643/4jmtbg4...Offlinedoc emotet ext epoch3 Cryptolaemus1
2020-08-25 05:57:04https://amcoitsystems.com/wp/public/9643/4jmtbg...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-08-17 07:43:03http://amcoitsystems.com/wp/ZxXBfZxSe/Offlineemotet ext epoch3 exe Cryptolaemus1
2020-08-17 06:53:05https://amcoitsystems.com/wp/ZxXBfZxSe/Offlineemotet ext epoch3 exe heodo ext Cryptolaemus1
2020-08-14 05:26:04https://amcoitsystems.com/wp/esp/n7kphoj/Offlinedoc emotet ext epoch2 heodo ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-25 05:57:04c34a3b0dbb2cb9b1ce9d7692d84317ed99bb887296c15debacdee800f1cddededocHeodo
2020-08-17 06:57:366d683c9b17bdc85e51db6edae6ede60efd0d2de777a5bd5c0791300dfb88b111exe Heodo
2020-08-17 06:53:054e3898cc5acb90a1bb07166316baa5f26357ccadea977ebe6501af72ae7a1f00exe Heodo
2020-08-14 05:36:25e3492d2065690769a6a42df6b2d8f81e652704ea415f5438639668d023f8fd2cdoc Heodo
2020-08-14 05:26:040f80316b76262700a25c47fc972ed9f77b1d2f997f7d8f4f2dc7c00a2c59eca5docHeodo