URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: balletmagazine.ro
Domain registrar: n/a
Domain registration date:2019-07-24 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-07-13 18:56:04 UTC
Total malware sites :1
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-30 07:59:59 185.53.178.99Not listedAS61969 TEAMINTERNET-AS- DEyes
2025-10-24 07:48:16 185.53.177.54Not listedAS61969 TEAMINTERNET-AS- DEno
2023-01-26 09:17:44 188.215.244.191191-244-static.mxserver.roNot listedAS44043 Cyber_Folks-RO-DC_CLJ- ROno
2022-07-13 18:56:05 188.215.250.187server.balletmagazine.roNot listedAS44043 Cyber_Folks-RO-DC_CLJ- ROno
2022-10-08 16:39:41 188.212.156.205cloud202.mxserver.roNot listedAS44043 Cyber_Folks-RO-DC_CLJ- ROno
2022-07-18 18:50:30 104.21.96.107Not listedAS13335 CLOUDFLARENETn/ano
2022-07-18 18:50:29 172.67.176.225Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-13 18:56:05http://balletmagazine.ro/wp-content/9VrMPV/Offlinedll emotet ext epoch5 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-13 20:08:5873490d0f86a34f6d1436aa0aa762cec0abae0bead19263fdd4def2e0483f9da7dll Heodo
2022-07-13 19:46:320d58662e3ee3901e84c15ad17b5b60a4d3e287e3fa1ec5a9b68c21a7143faeffdll Heodo
2022-07-13 19:37:5568f7e9e4a3ba7e7043365452c3a0ab98d844c5d336d32fd3cfc322a56dbb6a89dll Heodo
2022-07-13 19:12:25bd4684db2bc389629ed44f30d7a151215217686cad55326d538e2144bb10ecdbdllHeodo
2022-07-13 18:56:049307ad823e3b90612a20329b031eef134712f37f446ed562e8e5b372ba68ad22dll Heodo