URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: amphy.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-14 16:24:32 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 16:55:51 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 16:55:51 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2020-11-06 05:30:16 34.195.64.241ec2-34-195-64-241.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2020-09-14 16:24:33 192.99.46.39ns515977.ip-192-99-46.netNot listedAS16276 OVH- CAno
2025-09-11 10:37:05 104.21.77.155Not listedAS13335 CLOUDFLARENETn/ano
2025-09-11 10:37:05 172.67.209.145Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-14 16:24:33http://amphy.com/sys-cache/u2lxfd9s7t/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-15 06:13:15807bf4c0dd85eea9b4ea5c41fab297064a1a79599cf41ee23eddea254c4f5692docHeodo
2020-09-15 05:17:277432c22b6a99281670f18f32f78f9631d8b04c2715337de620a57debec0ce02bdocHeodo
2020-09-15 04:52:2211457a99a5505f705c398e4e05548708cc0ca4e18748421ea1374c0f410eb5abdocHeodo
2020-09-15 04:35:11221d824e80d3e36d5d0f52d1a0160382272e6d733a596f2eef49140f3823ad4bdocHeodo
2020-09-15 00:15:303101660852449fb80ba31c9c0dbb29ffd2c33de28fcf1e2080b3ec6594f4f963docHeodo
2020-09-14 23:44:33f4b770344e78791146677dc8e1fa4d56fcb574605948de9381aeaab6a0b9bf74docHeodo
2020-09-14 23:15:00b3c6abf670480a16083371fbbe54e43aae5e790eff0aa861813e51e44ca2c975docHeodo
2020-09-14 23:00:135e9694ee68dfea978dbc805fe72b5788f079caf4dc6e7cd66c811286bf943772docHeodo
2020-09-14 22:38:55693f393b73fba1545bbfed68995e08a5501d14fbb9904c4411e27245b75aef91docHeodo
2020-09-14 21:40:384d58f9bc9cb9c71282fc9003acfff87afebaa80186b02cbd42d663d20eb5c43adocHeodo
2020-09-14 21:27:5252cacf28b237a0c90d4a49fd44192565cda0c2ce66fcec9e082fc36bfd4ba4f4docHeodo
2020-09-14 21:23:085b34fdfd16c49176f9e6e5cdeb255aa73c18c4ef0648c89118cb1b17b52c8f13docHeodo
2020-09-14 20:59:5444cca8cba5ff51e2195e4c42279930fec3adf0cec60c38f0827e18f52070cd95docHeodo
2020-09-14 20:36:5252fc0bc99c65b0394f76bff61aec92b537d81777782b346228008e19424b4642docHeodo
2020-09-14 20:14:1126f08e160cfca8f495a847e27d56a77374220ca6245eaf0ae508c37fa408c910docHeodo
2020-09-14 19:52:20b5098ef2dd14c5067783d680242e7f0ccddcc4e2cf980639a3b3f0a03b6b1045docHeodo
2020-09-14 17:27:049c0736822b16dccce2ff3c10aa4f76237572ee96ad1573858b1cdcab41fee505docHeodo
2020-09-14 17:06:153e64b6ff86edb967541e4c0b1dc3667ccbd807e99af91d16f9682597b1352ee1docHeodo
2020-09-14 16:43:235d29d4ae2581a27221609c7e3877aa9139dd44042bcde1fb62d7e901d285e4f4docHeodo
2020-09-14 16:24:33a153e7d47a196c8848cbd1aa6b81d15adb43a1cc0c6402dca515ea34723c0ca9docHeodo