URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ankurtimber.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-26 23:48:04 UTC
Total malware sites :1
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-06 12:40:05 13.248.196.204a64c2b794233c60a6.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2020-11-06 13:52:54 62.210.142.192powerdns.serverbox.ind.inNot listedAS12876 AS12876- FRno
2020-10-01 21:29:05 148.251.129.209static.209.129.251.148.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno
2020-09-09 14:08:40 148.251.140.187static.187.140.251.148.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno
2020-08-26 23:48:05 95.111.254.124vmi604558.contaboserver.netNot listedAS51167 CONTABO- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-26 23:48:05http://ankurtimber.com/wp-admin/public/05253198...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-27 08:00:40f1f1a70cbcf4405ba3d4a322d81379f5346c3b56cb38edf6349042572e1752f1docHeodo
2020-08-27 07:31:0008531c896c900816e373957872ce7e55db50203fd681019719dca8fc27882b40docHeodo
2020-08-27 07:11:29982ec1619efb871fbcb238050b05cb55e526b8ea31b8759bde9e20c45ec482b8docHeodo
2020-08-27 06:53:018961b61c4631b8c84367078e44fc1066f57830e0bc0622af1de7769f82e6442edocHeodo
2020-08-27 06:38:19f663b206e32202cdb2b7fe26738d009a4c1fb76352cb8e9a46bd1a7bc6060bb3docHeodo
2020-08-27 06:22:562bae2742fb283aa2f35ef1722797919ff00e34f7e1868ca7841fc5baafdefe96docHeodo
2020-08-27 06:02:16dcab189bda6e7d076cfbc0f53566282de853a7676cf630a340bb8fd1288adfabdocHeodo
2020-08-27 05:47:49c741db44bb434a01cb739da0ba7df5ad5e396e7a3a5afcf79c11d071a5339b4bdocHeodo
2020-08-27 05:30:407f33bcae335d18da18a8cd7474dffc2399131f6e66ce9e7a8099718810cdd350docHeodo
2020-08-27 05:17:296618ae9fbbf615266ce3a04226305b4569758644d9bab2b4c4b4f116c96855b4docHeodo
2020-08-27 04:43:09dbfbc13ff098e5c8ed87a620e5e73f075dc9ac85963d50111843d28ea929a4d1docHeodo
2020-08-27 04:26:07869da97b04259da0e14dda9364d9575b02fd770b1fe8802f8145372cc503bba7docHeodo
2020-08-27 02:55:55b87a064c66cdd9719e97ee49c21b6435c4f769164c1195b5d14cf15b9dc81a19docHeodo
2020-08-27 02:38:58e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259docHeodo
2020-08-27 02:21:19f92eeeee023f763c255c41615d314bdd95628f511d7650771f8bbe9ef73742b9docHeodo
2020-08-27 01:59:52a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6docHeodo
2020-08-27 01:44:33b27e8c6c5a1f2ca799c9e70469734034437ef96227b7c5394ab56dc4d55ca8b8docHeodo
2020-08-27 01:25:06cade1ffeb7c4023e29d6f908dd96b6ef4f6d21c0a78dfb0728a0b358302e7563docHeodo
2020-08-27 01:06:07f0f0b47493858a336750af576adda44472e0e356aee227c530620df0f158e3b0docHeodo
2020-08-27 00:48:374d847d5aa9631703c559d3b4bf97eeb7d2a9f606fadaf1be40a1236b867481a5docHeodo
2020-08-27 00:35:41763a511d6b6e45d6386a286c0da9cc275171965046f20bf30ba106f6dedc740fdocHeodo
2020-08-26 23:48:054168ae4d976587190815be7c87622a09ba3a2cbd4f4d04b60de01b4794f0e54bdocHeodo