URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cat.xiaoshabi.nl
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2024-10-27 10:27:04 UTC
Total malware sites :11
Online malware sites :5 (45%)
Offline Malware sites :6 (55%)
Newest active malware site :2025-08-16 12:45:13 UTC
Oldest active malware site :2024-10-27 10:27:06 UTC (Age: 1 year, 7 month, 7 days, 8 hours, 32 minutes)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-12 10:47:21 45.221.99.101spk.cloudie.hkNot listedAS140869 TGL-AS-AP- ZAyes
2025-11-12 06:55:44 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2025-11-12 06:55:44 188.114.97.3SBL691350AS13335 CLOUDFLARENETn/ano
2025-09-05 20:10:11 103.119.13.4unknown.itsidc.comNot listedAS140869 TGL-AS-AP- USno
2025-03-23 14:14:29 156.225.81.99Not listedAS140869 TGL-AS-AP- HKno
2024-12-01 08:39:15 65.75.209.59Not listedAS50131 SPARTANHOST- USno
2024-11-20 09:08:04 111.243.73.205111-243-73-205.dynamic-ip.hinet.netNot listedAS3462 HINET- TWno
2024-11-20 01:58:04 111.243.112.21111-243-112-21.dynamic-ip.hinet.netNot listedAS3462 HINET- TWno
2024-11-06 02:56:19 111.243.89.152111-243-89-152.dynamic-ip.hinet.netNot listedAS3462 HINET- TWno
2024-11-05 12:21:45 111.243.111.27111-243-111-27.dynamic-ip.hinet.netNot listedAS3462 HINET- TWno

Malware URLs