URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: behsaude.com
Domain registrar:GoDaddy -
Domain registration date:2021-11-19 17:31:01 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-09 17:06:09 UTC
Total malware sites :1
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-24 16:47:12 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2022-09-14 01:06:58 162.241.2.70162-241-2-70.unifiedlayer.comNot listedAS19871 NETWORK-SOLUTIONS-HOSTING- USno
2022-08-01 23:21:32 65.108.77.176static.176.77.108.65.clients.your-server.deNot listedAS24940 HETZNER-AS- FIno
2022-08-08 02:11:23 82.202.194.13filternatin.comNot listedAS49505 SELECTEL- RUno
2022-06-19 03:24:01 144.202.17.238144.202.17.238.vultrusercontent.comNot listedAS20473 AS-VULTR- USno
2022-02-05 23:53:46 45.156.23.13Not listedAS56971 AS56971- NLno
2021-12-09 17:06:10 143.198.21.182Not listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-09 17:06:10https://behsaude.com/mgecji/OsxACzx66Q1lexCvMy4...Offlinedoc emotet ext epoch4 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-09 20:23:40e167804a6f36dc99e96909bcededa8a733dd8633037b8b52e8d7881d20446c16docHeodo
2021-12-09 17:06:105b0eadb028eafbc9bb1285c63f7a0fc68a235c037f04e81324474972367ccfe1docHeodo