URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 08:29:21 | 13.248.148.254 | aba1c1ff9d2ec5376.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-04-27 08:29:21 | 76.223.26.96 | aba1c1ff9d2ec5376.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2020-10-29 10:01:08 | 93.159.252.46 | Not listed | AS34953 RELAIX | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-10-29 10:01:08 | https://blog.opospalia.eu/wp-admin/k/ | Offline | emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-10-29 13:06:26 | 185d2dd0d7ca035e4cfeb4cd0f46e13a7283b4df7ba5bd8b4d7cfd1fc080a399 | exe | Heodo | |
| 2020-10-29 12:36:16 | 04c73b520399fd59ba51a5e60589841cf5ac35555a401bf30df856d5d7ce1d21 | exe | Heodo | |
| 2020-10-29 12:16:38 | 8cb7e4378a65922456a008f1f49527f0483b2619264468bb2b2167e2cbad0ada | exe | Heodo | |
| 2020-10-29 11:43:56 | 4af25f74c6561413e6696b6e66643af7a3297c06aa8dfc79dddc02c7884d3591 | exe | Heodo | |
| 2020-10-29 10:01:06 | 33fe6ab18b66d8d0dd55c8edc9d1378db5e553bf381c9dd73499d6dfec991021 | exe | Heodo |
US
DE