URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: aquarius.com.br
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-21 09:40:06 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 19:08:21 191.232.188.173Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- BRyes
2020-09-22 03:05:36 40.65.236.192Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USno
2020-09-21 09:40:09 40.70.185.148Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-21 09:40:09http://aquarius.com.br/9hv3/esp/EHSmAJcYxP1ic60fz/Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-21 19:26:08d3ff202740cdff416eec962da85987a787df2ae2fc8e6fdf4b010035594c9960docHeodo
2020-09-21 19:03:24817dfa0131f4686e1849deaf26ff7ffe1f5b2eb30526bc09a6753ce13185f502docHeodo
2020-09-21 18:41:40716299f97023ee3e7f0a20ad1843ee7284684da8a503b9031fdaf0aac7e81671docHeodo
2020-09-21 18:17:52fb5916b49a668daaac999ec4edfa053a580598228838e24dea97f07289f6a2f8docHeodo
2020-09-21 17:57:59fada4708605505ec08d2045110877e6a7cd8fb2037b0d9bc3c32c5607a23c21adocHeodo
2020-09-21 17:43:570adca8f3f5265407428b7bada83845928992378c6adcfaa2126c4b04f40ea987docHeodo
2020-09-21 17:37:372f702f1a2ba900b1f907315425309f855fc57073c9c5afea7bcd30e69ada2ed7docHeodo
2020-09-21 17:07:5366cb8b7e3c4085898b6efb2c9b2d39cb3bd28f6fab85e83e70b4e9a3f441a22fdocHeodo
2020-09-21 16:32:4380a8b5600bf204df850aadf7d4e7833263ef3c4771208d62fcb53e662007b5d3docHeodo
2020-09-21 15:56:558444b33aede1c4250ebffcce3e2abc7f96072003c7a5981b85a10bad9536ecaedocHeodo
2020-09-21 15:36:54dca654f7419186826dd804c032f8e751321489bd9949c76f41b996cd587ae19fdoc Heodo
2020-09-21 15:09:37d295a4bc76b3fcc18074cea9d67ed8b169bfa0d2c88f51d09bdc56d1db74de58docHeodo
2020-09-21 14:25:44356b82eeebe4eebc57579bc3932589783542b3b169a2f2c85dfa0c78fddb7ac1docHeodo
2020-09-21 14:08:168624b86a85ad6c756c26034225f489ef15aa8cfcfdf0dafb529ab9a1718e075bdocHeodo
2020-09-21 13:54:4842f29aa41b1f7d9de698db6b2a4512a76e4c54af72ab7ce26542fc3666438084doc Heodo
2020-09-21 13:29:045a4026c992939e304da0cb25bcf181141d3875dec80db0003434902ca37ec64edoc Heodo
2020-09-21 13:16:18c38007baa464dfca54ee9305c00ba166951dc23b5b4acf9fd9d28ae1ca04ca8ddocHeodo
2020-09-21 12:56:33a0953aa999c3d722ffa876f5dd3371023be5aa513d6ec18052edfcb2b7feb185docHeodo
2020-09-21 12:28:236cd088d70602d9032920e91bec900e3f28ba0a38eca2b98bd6139e6e882bed64docHeodo
2020-09-21 12:22:497a54b9e5d5090d615e8e104632ff7c966103ba016bdb7722525a3eb1aed17c13docHeodo
2020-09-21 12:07:25155fc45f0849e7a83587aedc0cb028a587bf371a518ceeebbd95492f5ee666dddocHeodo
2020-09-21 11:41:55067eb151263b210a180acec91b442c110a21200820760e17f408b1fbbfe4f67adocHeodo
2020-09-21 11:26:22e31852589616b85edbf925aabe05c088a34bf27428fb8b11d1908d227b8bcb37docHeodo
2020-09-21 11:08:27b556e5b6ae3087d8ffa1327e4115618e43c66602e8a877abf50d008861d7b740doc Heodo
2020-09-21 10:48:10c011f657db09823eeda192e8f301d95cd0abb5aa4fac1ef4d53c5169e951bbf0docHeodo
2020-09-21 10:26:103e852ee596953598ade5ec15aca21d6360f378edb62269d0b2d2c9ae5c8d3bc7docHeodo
2020-09-21 10:06:36d8fa1fd9d6875f094c2397135903ec7e871ca63b06a471a6052b8cda6d7b208edocHeodo
2020-09-21 09:40:07197e6b7ab5d8d561afd038bad52a5be5c5f9134eb8c8d04ba5f64124c211baaddocHeodo