URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: btqonline.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-15 18:24:33 UTC
Total malware sites :1
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:28:51 76.76.21.21SBL688052AS16509 AMAZON-02- USyes
2021-02-10 00:49:45 13.248.216.40afdda383cf24ec8c3.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-01-18 06:22:03 34.206.12.234ec2-34-206-12-234.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-01-18 06:22:03 54.208.77.124ec2-54-208-77-124.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2021-02-10 00:49:45 76.223.65.111afdda383cf24ec8c3.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-01-18 06:22:03 35.169.58.188ec2-35-169-58-188.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2020-09-23 09:53:04 160.153.210.198198.210.153.160.host.secureserver.netNot listedAS20773 GODADDY- USno
2020-09-15 18:24:34 104.18.52.194Not listedAS13335 CLOUDFLARENETn/ano
2020-09-15 18:24:34 104.18.53.194Not listedAS13335 CLOUDFLARENETn/ano
2020-09-15 18:24:34 172.67.174.143Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-15 18:24:34https://btqonline.com/websiteguide/swift/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-15 19:14:13ae651bbc1bb9cb216ddeae09b03346aa86c991c00d59ad680a83343eac0d4da2docHeodo
2020-09-15 19:10:1381834b464c9d4cf11ffc357df7e18071f8e5d8f62d182e997059da665294a8b2docHeodo
2020-09-15 18:41:48c8410c8dd820bc1e8805ba93260cd2fb0f7707d75573915bdb97ea2a01b66ea8docHeodo
2020-09-15 18:24:34567b914c19e54fb78b9c487868550a0ead98ccc21e1f640d571b7d98ad1e13b1docHeodo