URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: baihutou.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-26 20:29:03 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-18 05:34:57 47.76.127.217Not listedAS45102 ALIBABA-CN-NET- HKno
2025-08-18 05:34:57 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2025-08-18 05:34:57 8.218.208.240Not listedAS45102 ALIBABA-CN-NET- HKno
2020-08-26 20:29:06 150.109.42.226Not listedAS132203 TENCENT-NET-AP-CN- HKno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-26 20:29:06http://baihutou.com/wp-admin/OCT/v8e2bq24hlo0-067/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-27 06:53:2600993b12381962ddf42f0785a5a6660035dea597c5782a819714f2ce29ba2701docHeodo
2020-08-27 06:38:20de3a26eecedf1be057cea2d07ee52ec75fa41f8b7a3a00ea7d1a4920d971c902docHeodo
2020-08-27 06:24:342bae2742fb283aa2f35ef1722797919ff00e34f7e1868ca7841fc5baafdefe96docHeodo
2020-08-27 06:02:11021d2338b8a706fbd77f04cf43db3bf9dea03a1afff732ece042614c35e369eddocHeodo
2020-08-27 05:47:14518cef1391f1fd9cabab66c2c32f6ee1428a399147f181ff433baefecb0e8c45docHeodo
2020-08-27 05:30:357f33bcae335d18da18a8cd7474dffc2399131f6e66ce9e7a8099718810cdd350docHeodo
2020-08-27 05:17:506618ae9fbbf615266ce3a04226305b4569758644d9bab2b4c4b4f116c96855b4docHeodo
2020-08-27 04:58:55469ac8a418f2dbb4e433d022cc757fe2ddb270878b4c7ab13ebf4f8a316c30e6docHeodo
2020-08-27 04:41:45dbfbc13ff098e5c8ed87a620e5e73f075dc9ac85963d50111843d28ea929a4d1docHeodo
2020-08-27 04:26:04a7de5e7039339ecbff062dcb58d75a469ea8240a5f7d1549f67e69e56443865cdocHeodo
2020-08-27 02:55:48e0cc6b1684c8b8e688fb1f1a48960cb333e7001b6b8aef55314c0a4cb3ef74a5docHeodo
2020-08-27 02:39:04e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259docHeodo
2020-08-27 02:23:010cbddd5eeb728ba41f56bd3066629b9ad20536c1373057891cc5ea201d70c2d2docHeodo
2020-08-27 01:59:32a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6docHeodo
2020-08-27 01:45:22b27e8c6c5a1f2ca799c9e70469734034437ef96227b7c5394ab56dc4d55ca8b8docHeodo
2020-08-27 01:25:04aa6642f3646a47adb129237f6b98cae77adf136b5e30fd9f9b2c05219fd730d0docHeodo
2020-08-27 01:06:10f0f0b47493858a336750af576adda44472e0e356aee227c530620df0f158e3b0docHeodo
2020-08-27 00:48:424d847d5aa9631703c559d3b4bf97eeb7d2a9f606fadaf1be40a1236b867481a5docHeodo
2020-08-27 00:31:4645c6293b87ea5ec369c3130d674caf51a96048a1fdd88636c9c15626edf8b375docHeodo
2020-08-26 23:00:58b11bd4b83e89bc246bf2b88dba510f02dfbeb9742d55087260bfeb43f0049000docHeodo
2020-08-26 22:49:53c0b72b161a48dab0be1f4cf804079f65cae5827a62e982b8af3fe00a2281dc0fdocHeodo
2020-08-26 22:26:414e2e9c00a518654ed11ca5bdbcb739c816524d665f519789f77cad7c1ee6d78cdocHeodo
2020-08-26 21:56:19900e897c3d7f08039833fa89748e84c98a62d959e4e8e8cc54c832acd902470ddocHeodo
2020-08-26 21:33:126ed646f54add9ca22852e2fbe34861573a88cadccac53c9ccdaeffe7db82d284docHeodo
2020-08-26 20:29:051862df6f40d11380f7d581fd9f613d34ff81f2f61ca92d8178a226434543ff52docHeodo