URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-17 22:40:18 | 188.114.96.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-09-17 22:40:18 | 188.114.97.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-09-19 04:03:27 | 104.21.20.131 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-09-19 04:03:27 | 172.67.192.233 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.112.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.16.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.32.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.48.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.64.1 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-04-29 07:04:34 | 104.21.80.1 | SBL681411 | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-01-21 04:54:09 | http://arqua.com.br/siteantigo/gYDoYUIWNgc8kTHD... | Offline | emotet | |
| 2022-01-21 04:54:06 | http://arqua.com.br/siteantigo/gYDoYUIWNgc8kTHD... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-01-21 07:08:52 | 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5 | xls | Heodo | |
| 2022-01-21 06:49:19 | 5733b0f4ff735d3282e9f35d49f2415eb5b786859209d98bdfeb412b55d09958 | xls | Heodo | |
| 2022-01-21 06:38:08 | b11d267860a7dfa12d415540e8d6b6e4b7813b2a4d633c966ce2c405a20b9a95 | xls | Heodo | |
| 2022-01-21 06:21:06 | 245057c2c16d698dc5399ecd43ca39f9e0b35885a19cc42cd2650eb8e17d0c00 | xls | Heodo | |
| 2022-01-21 06:00:34 | 39123bd1932920eca6749593bee628c405f8bb88114d8647a5d9db8b5914f46c | xls | Heodo | |
| 2022-01-21 05:38:11 | 08e9cfb42b052e00b6236416ac76a10be4787f0ec137401a92bce8fed5f84d48 | xls | Heodo | |
| 2022-01-21 05:10:22 | 03f8ab0e08386a7dcad36af464f60e8e879787d760562de70588313f7668f83c | xls | SilentBuilder | |
| 2022-01-21 04:54:09 | 046d8bfa22515394836d0358372ea11050ba74ac2efa078682ff27a18d089feb | html | ||
| 2022-01-21 04:54:05 | 09cac9c9cb6daf68f51433121e6e0678e7c9703512d4abb09623c1363ab92689 | xls | Heodo |