URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: blackmarketantiques.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2018-11-28 13:33:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-30 14:46:03 23.227.38.65myshopify.comNot listedAS13335 CLOUDFLARENET- CAyes
2025-05-25 21:08:34 13.248.243.5a16e665f42988324c.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-05-25 21:08:34 76.223.105.230a16e665f42988324c.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2019-01-16 08:56:08 184.168.131.241241.131.168.184.host.secureserver.netNot listedAS26496 AS-26496-GO-DADDY-COM-LLC- USno
2018-11-28 13:33:06 64.20.54.219blackmarketantiques.comNot listedAS19318 IS-AS-1- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2018-12-04 14:28:23http://blackmarketantiques.com/J17M/Offlinedoc emotet ext heodo ext Anonymous
2018-12-03 09:46:17http://blackmarketantiques.com/rc46Z4bPh/Offlineemotet ext epoch1 exe heodo ext Cryptolaemus1
2018-12-03 09:46:06http://blackmarketantiques.com/rc46Z4bPhOfflineemotet ext epoch1 exe heodo ext Cryptolaemus1
2018-11-28 13:33:06http://blackmarketantiques.com/J17MOfflineemotet ext epoch2 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2018-12-04 17:37:277641027a29cc6e90041e3054db745e3f2a6d9dc2ab7ecbbfd16c05c8fd49e03cexe Heodo
2018-12-04 17:37:277641027a29cc6e90041e3054db745e3f2a6d9dc2ab7ecbbfd16c05c8fd49e03cexe Heodo
2018-12-04 06:20:44a6492280560d012bf18891908b905f993b231cde63a1311ede6d59a61371a34fexe Heodo
2018-12-04 06:20:44a6492280560d012bf18891908b905f993b231cde63a1311ede6d59a61371a34fexe Heodo