URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: decorgc.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-24 11:13:34 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-07 18:05:25 13.248.213.45a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-07-07 18:05:25 76.223.67.189a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-06-28 06:27:54 15.197.148.33a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-06-28 06:27:54 3.33.130.190a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-04-28 02:43:49 13.248.243.5a16e665f42988324c.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-04-28 02:43:49 76.223.105.230a16e665f42988324c.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2020-02-21 09:45:02 198.71.232.33.232.71.198.host.secureserver.netNot listedAS398787 GO-DADDY-COM-LLC- USno
2020-01-24 11:13:35 54.36.167.79ns3143017.ip-54-36-167.euNot listedAS16276 OVH- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-27 20:16:39http://decorgc.com/wp-includes/yo57-5rs-9848/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-01-24 11:13:35http://decorgc.com/wp-includes/EjmMUhrRX/Offlinedoc emotet ext epoch3 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-28 01:44:5437f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbdoc Heodo
2020-01-28 00:46:146f7ef2942319a8f55b338d43ac0717e2999baaf867ba160e6cdc15c85b47a4e1doc Heodo
2020-01-28 00:16:474894a2fb49eee40ed615f4dc24ee4965b5343992df774c0871b9f6d6cc7c6f97doc Heodo
2020-01-27 23:39:2411c1f2089f30fba10c0d8e7a46d5b5a163acc645ae1ac899f9c1da16fd34d5cddoc Heodo
2020-01-27 22:07:204ec6f4e3c42c761d38c46394803e40b4a8e590ee2baa48b27ace184f052c7546doc  
2020-01-27 20:35:19b8234c3a29dfe136921812c6011604fac4f3860df104d73b44365fd690d34e17doc  
2020-01-27 20:16:3926716801d331a491cae621756905e7ae448691f6fb811f68ea329e6f433bd32cdoc Heodo
2020-01-25 01:26:37983ddd1518361a6f16f1b4f4980f9f8e195ab46794ddb14935f83c5a93781f17docHeodo
2020-01-25 00:25:452b5ca64e42cef50cfb9ace4245c80f04386d418c75fca3e1936a02b03f2b9690doc  
2020-01-24 23:53:19d1a8632d5649ad116f4f6afb521b86b8820ddfe5857577cf7a01954e9195a7c2doc  
2020-01-24 23:24:51367dfc1505c5c9b6c114c2a8b2b9604b8fd894ce90371f8f6eeabf3f029280d6doc Heodo
2020-01-24 21:53:38a83d0f30a2ee74323fb78fd55b642779d7064f8392525e99dfd2bbfe947e2e48doc Heodo
2020-01-24 21:05:07f632cc29e85b046da247d72a74114c3d50dec27be7e5bae146b9622e2542e59adoc Heodo
2020-01-24 20:50:504982421b347ca1f4b3ad1ffc6c6bbbef2ad9fb126ef18e2db576a1a5bdc39163doc Heodo
2020-01-24 19:36:37523d406a32b4b4f1220d4640035d0a61410d4fda51546574e0340650b6cc61e8doc Heodo
2020-01-24 18:05:28c5ff285a941ab8a9177014c4da25f781d545ce5465186d5a1a674e3ee4032476doc Heodo
2020-01-24 16:55:201794021229640d080ec671b9c7262e9941c79cf43c48c22d1c4b5297212f0014doc Heodo
2020-01-24 15:36:3758f4a9350c2c4d061072015bf56382f773719d9d78ad3bba260cece6dce54e54doc Heodo
2020-01-24 15:22:572d4faab5324229be37231e2fc6d6b430579e396fcdf4db46867cf7f7b04e90f5doc Heodo
2020-01-24 14:05:1991716865af6c80fca3ecac4d0d46ce403b4e7374fd8b651d19a1b98d4ae55b93doc Heodo
2020-01-24 12:39:379e7cdaa56cdc7f791acec407618bda0eed9992a0adfe090208b17f472aed4119doc Heodo
2020-01-24 11:13:35d4a5dec72600091f43cc79f5efc5b76ed09571f1a906a6fe4400b3ff08341638docHeodo