URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cosmetics.zone
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-22 20:18:02 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-11-05 20:06:53 18.224.118.141ec2-18-224-118-141.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-11-04 19:25:10 3.136.35.220ec2-3-136-35-220.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-10-28 20:16:56 3.14.206.87ec2-3-14-206-87.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-10-28 20:16:57 3.140.94.226ec2-3-140-94-226.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-11-03 15:54:50 3.142.112.3ec2-3-142-112-3.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-10-28 20:16:56 3.20.112.42ec2-3-20-112-42.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-08-12 04:23:56 99.83.154.118a51062ecadbb5a26e.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-01-22 20:18:04 104.21.67.213Not listedAS13335 CLOUDFLARENETn/ano
2021-01-22 20:18:04 172.67.181.96Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-22 20:18:04http://cosmetics.zone/wp-content/ESNZUkGcCWBfHE...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-22 23:37:23106d381e6f7de228eeca31e1ff0745404f3277db77946b9c462163b70bd5dd1edocHeodo
2021-01-22 23:30:5925eae8684f15cff80197f955eff7899e81081b1d9dd37eb92f62d7bb8bd796addocHeodo
2021-01-22 23:22:3458679381a46d62f343527eddb0e188a30184ea770eac5182c427ff13ec75412cdocHeodo
2021-01-22 23:07:45a9298f2707a11dfbafc02b9880250f2fde9e11b3ed26c80bd952ee4c5f41c667docHeodo
2021-01-22 22:56:575705fd96f5d9b9500a5efc36a759c276ba912d8eda40677ed5d0fa58f1a843e0docHeodo
2021-01-22 22:40:07df60461aab62bf09077b67a5fd122fa46ed22f8a8d184035786a7ee3be961927docHeodo
2021-01-22 22:25:55dda4d5d6a43a16422b43d2303fca26fdda00b3b7836e9aff4ddbdd19442d9697docHeodo
2021-01-22 22:13:09572f2066bd622ffae9324046ef4e96026a4bff32a177c91ea779269d75ac98b7docHeodo
2021-01-22 22:03:41e86d93199f2f416bf5dca9a736c5bdbac4ee3989ab0f04baad2c7e0066316e72docHeodo
2021-01-22 21:49:39d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1docHeodo
2021-01-22 21:43:118af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3docHeodo
2021-01-22 21:25:199849abef3e272dea13e211d946b289bc80ab32efd5e83178ca17a6bb094be274docHeodo
2021-01-22 21:16:30dda31bb204e2a3207fe515d3d1952604f010c2b3bfad0df8a1b33e7b4bde2b94docHeodo
2021-01-22 21:04:54912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24docHeodo
2021-01-22 20:27:10d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97docHeodo
2021-01-22 20:18:041cc3ce82c3d5c07a7ad73b7890969696e032964b0773b29a1f21a68dc55e23d6docHeodo