URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 07:32:17 | 51.79.79.189 | barima.tepuyserver.net | Not listed | AS16276 OVH | CA | yes |
| 2020-07-28 10:54:10 | 192.99.63.2 | ns525533.ip-192-99-63.net | Not listed | AS16276 OVH | CA | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-07-28 10:54:10 | http://amppe.com.br/wp-admin/USiYWck/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-07-28 13:09:27 | 54171a3ad4b125dc2795767c4e783e474bddf5f973b21bfaad94b3d15057b763 | doc | Heodo | |
| 2020-07-28 12:30:39 | 0034fc70978e5e2fbd485351d863a0f1f6eb072e56cf5eac63df39bd8aa5bf40 | doc | Heodo | |
| 2020-07-28 11:58:48 | 814e3bf4e6588ecf751e5808d868435ef992cf6b301d534341fb90d254f91cfe | doc | Heodo | |
| 2020-07-28 11:37:51 | 8330eec3e5619dfe033c6d7059a8b53f1cd6319c5960f917d5b4472534fa349d | doc | Heodo | |
| 2020-07-28 11:37:29 | 8330eec3e5619dfe033c6d7059a8b53f1cd6319c5960f917d5b4472534fa349d | doc | Heodo | |
| 2020-07-28 11:16:07 | 0e447707a2cdeef876e102f3abda24f1258292d7396aa4578f55049feb5bda64 | doc | Heodo | |
| 2020-07-28 10:54:09 | 4bc6f4a851f7b881e137ea06cd3c9567e372ea91e2c447036f4d2f0e6255ec82 | doc | Heodo |
CA