URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: demonware.online
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-05-16 12:43:04 UTC
Total malware sites :1
A record(s) observed :23

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 11:37:34 91.195.240.45Not listedAS47846 SEDO-AS- DEyes
2022-05-16 12:43:06 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2022-05-16 12:43:06 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2022-11-19 18:22:47 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano
2022-11-19 18:22:47 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2023-02-24 01:51:35 188.114.96.7Not listedAS13335 CLOUDFLARENETn/ano
2023-02-24 01:51:35 188.114.97.7Not listedAS13335 CLOUDFLARENETn/ano
2022-05-26 23:54:07 188.114.97.0Not listedAS13335 CLOUDFLARENETn/ano
2022-05-26 23:54:07 188.114.96.0SBL686925AS13335 CLOUDFLARENETn/ano
2022-05-16 13:05:52 104.21.17.63Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-05-16 12:43:06http://demonware.online/AuDemon1/dashboard/prog...Offline32 exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-06-01 23:39:193d275fea302f5bab0d04f70d85de674f6abb72fab1d7db87c218cf5976da1ac6exe  
2023-03-06 21:15:003d7699832c4dc30a4a73308ac294f3be2d23778864b3757b6a58a38e10f5326fexe  
2023-01-11 09:02:08ca9ea2e7431d0da5d8f8e3b4054184c7135805cd2776842444dc4a60f0f6913dexe  
2022-08-17 18:14:36d26e1cb039d09ed9adf136a5f290b01d3fa0b35ddb95ac2fa04dd15ed145c439exe  
2022-08-10 17:35:3456f8ae98568bbfe3291bfdad9797b5ab88ca40eb91a8eaa3f969de360dc94797exe  
2022-05-16 12:43:0634780db137a84afc3d8957def954127c724fba4187055e49b875481203b68163exe