URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: balanceathlete.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-21 07:47:05 UTC
Total malware sites :1
A record(s) observed :39

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-06 03:03:28 15.197.167.90afa7f374f51cc8991.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2021-12-05 00:44:25 23.20.239.12ec2-23-20-239-12.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-12-03 23:15:58 18.211.9.206ec2-18-211-9-206.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2021-09-02 18:34:08 3.223.115.185ec2-3-223-115-185.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-06-27 03:28:22 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2021-01-21 07:47:12 185.43.108.196us95.acugis-dns.comNot listedAS62217 VooServers- USno
2021-12-03 09:07:40 34.197.51.118ec2-34-197-51-118.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2021-12-02 16:50:47 54.82.71.19ec2-54-82-71-19.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-12-02 16:50:47 34.199.50.82ec2-34-199-50-82.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2021-11-23 15:15:11 34.202.26.144ec2-34-202-26-144.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-21 07:47:12http://balanceathlete.com/zbf8jiX.exeOfflineexe njRAT ext QuasarRAT ext oppimaniac

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-21 10:59:51791892ba1ee116dc8b35ad80be2dd5525a07cad2e2cd9966b2604c121b3b9670exenjrat
2021-01-21 07:47:101f8dd197b62c9f620d9edf72be1e4154a5fc9c847eee5e68a2382f0a9613fb79exeQuasarRAT