URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: bluecovertrading.com
Domain registrar:GoDaddy -
Domain registration date:2018-11-08 07:22:42 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-04-26 09:21:03 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-13 14:48:52 13.248.213.45a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-11-13 14:48:52 76.223.67.189a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2022-11-25 05:20:13 165.22.219.50623269.cloudwaysapps.comNot listedAS14061 DIGITALOCEAN-ASN- INno
2022-11-22 06:13:36 34.102.136.180180.136.102.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2022-11-14 03:48:40 34.98.99.3030.99.98.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2022-04-26 09:21:05 132.148.159.212212.159.148.132.host.secureserver.netNot listedAS398101 GO-DADDY-COM-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-04-27 11:13:05http://bluecovertrading.com/s/uchiorigin.txtOfflineexe vxvault
2022-04-26 09:58:34https://bluecovertrading.com/s/deviltelegram.txtOffline Cryptolaemus1
2022-04-26 09:44:06https://bluecovertrading.com/s/deviltelegram.exeOfflineAgentTesla ext exe Cryptolaemus1
2022-04-26 09:36:07https://bluecovertrading.com/s/UYEWUYEWEU.exeOfflineAgentTesla ext exe Cryptolaemus1
2022-04-26 09:36:06https://bluecovertrading.com/s/viks.ps1Offlineps1 Cryptolaemus1
2022-04-26 09:35:11https://bluecovertrading.com/s/uchiorigin.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:11https://bluecovertrading.com/s/dave.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:10https://bluecovertrading.com/s/ploki.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:08https://bluecovertrading.com/s/daveo.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:08https://bluecovertrading.com/s/ari.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:07https://bluecovertrading.com/s/xl.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/humble.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/DEVILTELE.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/BASE64.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/DACC.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/que.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/kooll.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/muhamed.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/waty.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/formbook.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/richard.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:06https://bluecovertrading.com/s/xloader.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:05https://bluecovertrading.com/s/blacksheep.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:35:05https://bluecovertrading.com/s/dun.txtOfflinebase64 binary txt Cryptolaemus1
2022-04-26 09:21:05https://bluecovertrading.com/s/mex.txtOfflinebase64 exe txt Cryptolaemus1
2022-04-26 09:21:05https://bluecovertrading.com/s/newddll.txtOfflinebase64 exe txt Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-04-27 19:29:54875239807b4afec0ff3b762bbb413cd92f3d109439517edf38f08e5d002bc147txt  
2022-04-27 14:43:07a6b47b1155bb22cd2e07298294801d6dcb0aa349db43d6d5e70c1411c748d4d8txt  
2022-04-27 11:59:4545b2313f34ea87c71a51207ddb52294420478925e2192c0f171ce267921e042etxt  
2022-04-27 11:13:056bc36081b1cd6134e753ed4486dad4c4eeecd0ae91747ff3a54ee026715cfb3etxt  
2022-04-27 07:56:1689e7eed9a82c0151406f0a41d3435f9927da46d9074f13e7b32b012d5cb2c76ctxt  
2022-04-27 04:31:47aa84df552ca2f63a3b70fc8ed1e0e5b74ce91aa54a06dee67c58edabcb1dd73etxt  
2022-04-26 20:07:14a3071756eaf1da2e01a96fa49a45df5c5b69b64f3567c75424cc1456bd07bfbdtxt  
2022-04-26 09:44:063d2e2ba113768dd048e1626c168c0285bc5bb1cdb740376364114f01a5f30638exeAgentTesla
2022-04-26 09:36:07117d7148a821fdcdb220b15102cbddf617c1e1267fd25abda1d8037b722e0af5exeAgentTesla
2022-04-26 09:36:06fbb7ca4cecc81a5885d762a43599ae81584aef789d4a6f8d193e8d8dccce3eeatxt  
2022-04-26 09:35:116bc36081b1cd6134e753ed4486dad4c4eeecd0ae91747ff3a54ee026715cfb3etxt  
2022-04-26 09:35:1010a4ff8a9f1d06feebb8cb5d14a9224de08e046017c39bf162a0aaafa469dd4ftxt  
2022-04-26 09:35:0868633986dfa2575cd4034cbf74d3dce746a4969ac79f4ea69e07f3758deb8b9btxt  
2022-04-26 09:35:0827fb5f412c2368ebaaa3baa6c8ce02c14d7f5a8e4b84c935eb3c8be49e040de0txt  
2022-04-26 09:35:070244dfb42ca8e391af65a87f425488c0b65ef0d7b1bf93f0f7fbdbe7f1576784txt  
2022-04-26 09:35:0636fdca735a14dbcabb56f21ae6b85f6c0bf70e342da525275b16457d40c5d48ctxt  
2022-04-26 09:35:0608f3104fc0021e70637046b64e0bc4fe8b6f2021a156011b30aeb8adfa364d91txt  
2022-04-26 09:35:06790c1e0026e8ed908ab05462c51881fcb44fd5b33047ebe802e40e648e1045f4txt 
2022-04-26 09:35:05bdf295b6ba9f855a926c3bd66b64fac9d2f20387f9f2f89ed767bf4ec51c0d3atxt  
2022-04-26 09:35:05046f425856be2ab54dbb04caf9d3e5d8ba041459de8606b7a40cd1073035c4abtxt  
2022-04-26 09:21:05d02ad18f9f97ca19c0d9a79fa0199ed6f020e4f9fee3e386b5007b2f2412be4btxt