URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: baharatgetir.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-30 13:34:03 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 04:32:17 15.197.148.33a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-04-28 04:32:17 3.33.130.190a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2021-01-13 14:05:11 104.21.6.92Not listedAS13335 CLOUDFLARENETn/ano
2020-10-30 13:34:05 172.67.154.215Not listedAS13335 CLOUDFLARENETn/ano
2020-10-30 13:34:05 104.28.8.230Not listedAS13335 CLOUDFLARENET- BSno
2020-10-30 13:34:05 104.28.9.230Not listedAS13335 CLOUDFLARENET- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-30 13:34:05https://baharatgetir.com/sitepage/jtGk9Nv7B8p82...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-30 14:10:3562e102b2ca91bf58fe507a7ef4318f7cdc68777ffb02ff3698b2d79c1729c807docHeodo
2020-10-30 13:52:176263b8ea9431ac48bf402098737c84a9cf49c01488319875132ef15ef7d5c6e7docHeodo
2020-10-30 13:34:05b86e09a5bdebde57bd67e1fa11ddbd3381e5972d091fdc61b68e34226fabf084docHeodo