URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: dominion.church
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-28 11:57:03 UTC
Total malware sites :1
A record(s) observed :17

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-08 23:34:28 13.248.169.48a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-06-08 23:34:28 76.223.54.146a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-09-08 21:42:49 166.117.110.61Not listedAS16509 AMAZON-02- USno
2025-09-08 21:42:49 99.83.161.153a2b7bf3398455f345.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-05-31 11:35:39 198.58.118.167li647-167.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-05-31 11:35:39 45.33.18.44li972-44.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-05-31 11:35:39 45.33.2.79li956-79.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-05-31 11:35:39 45.33.20.235li974-235.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-05-31 11:35:39 45.33.23.183li977-183.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-05-31 11:35:39 45.33.30.197li1047-197.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-28 11:57:07http://dominion.church/wp-content/attachments/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-29 16:47:33242de608bdf2c6fbfa037537be866bf7558858fc240142c606115e86bd28a941docHeodo
2020-08-29 16:26:4504736f2116906a635d71d83a8f1c49fcd6e2b8c79e89e19dba1a94b475408e33docHeodo
2020-08-29 16:08:21b39ab4983136519b6249443c1c9f1a89b7c1e83cd17ec40748745b41268741dcdocHeodo
2020-08-29 13:45:297bb6a59e90701bb2af8a195fe877681d0446710c6001ce3b05e2e87ac4860d37docHeodo
2020-08-29 13:04:257dc9821a27cbc29bddb4bb3c708aad0b24a82d9beb1a2df9caeabf7ea6bd8e06docHeodo
2020-08-29 12:43:301abfb23d0ef450db1e33f441e234e648df678ba7b2bf48ec1a2fe1ea9d657b16docHeodo
2020-08-29 12:26:003dd19fa3dfe1d9d6331fbd1a268039b10e39e85e47e85410b508ec06053179c4docHeodo
2020-08-29 12:06:25f209ab8d6f3245e310df1b4d869bc6aa15a8fbff5ae8977bae8cf3eb7151eb88docHeodo
2020-08-29 11:49:0434718fa71636dd5f6c1167c33eb160205b972ec6e3d9b4151756732c02131190docHeodo
2020-08-29 10:18:24ca7ffa1708bb416ae9e386f1a02b2d038f3e57bcfd56d68c0759eb10494aa5a8docHeodo
2020-08-29 09:59:4313df7d0cf9c4f67e22eb093ff92b70f61fe8e5c61d1afb6c933fee76f2525abedocHeodo
2020-08-28 23:50:20de518e6e375b2f26fb6424f1fc1846374bbe5128b0513a60b0494571f1d5ddc3docHeodo
2020-08-28 23:34:04f5d308b615528818047b9010074fd219d6248ce43aff167bcc0bbb56a6d45504docHeodo
2020-08-28 23:23:01aef46f7e71936aca8da4fff081f587fe6293f09dac7b27fc70f372088eff86f5docHeodo
2020-08-28 23:05:001dc29557a12be6e06387d45b6f9413598f9f48033cc483779a61f233d8986311docHeodo
2020-08-28 21:36:14e5cbe16ff82c0a8778906a889f99a6cc41def9921e1944cf107eab74e277559bdocHeodo
2020-08-28 19:24:51e189a7569815651cf514dcabf42ee4991cc49f7653402684fbf55db8353f7908docHeodo
2020-08-28 17:54:3845c6cbf3a848206d33f3a4d92ca9ac6f3511b39227d46e433887c00384ed6f56docHeodo
2020-08-28 17:30:17f5b03a311135b32ed372590430479a35b0e7c1538ffe7e95f60baf40732f350ddocHeodo
2020-08-28 17:04:236fb504f2fd1966b7eb00f0a9cdcbd5fc4cedbc4bc50d5d77702e61460e5230d4docHeodo
2020-08-28 16:42:15425659a7db67434fb846e86eb949e0ae4af1288284cfe1633ebd1229f20a9c55docHeodo
2020-08-28 16:24:034db3beb6f41d990761c52595af5d36a423bb30b32775df91f5bfd7438aad89b0docHeodo
2020-08-28 16:01:06e3ce3a99ec926db991576661b442a60aca41a86fd410508a544257b63a5cb4b3docHeodo
2020-08-28 15:42:34f4a8c680fd30bfcdeb471e51625dde88c3b97240656b50635930776ac46f3eefdoc Heodo
2020-08-28 15:14:58ebbbf1104be5c5f4f000285e72aa802cdac327750e71a35a101e4ecac224d1d2docHeodo
2020-08-28 13:42:1674fd5e51184bd860adf8fa2da123bfc7876d06d7ac5007da67eb4a56f54640a8docHeodo
2020-08-28 13:21:26ecec70a49cac590cb3d67dc6555fa9351fbbdfa81c00d8a2273e49527baa5463docHeodo
2020-08-28 12:57:58f49d9546a53d5b00619acd8dd32985c7475d25628ab997d7f6160250372fb2dfdocHeodo
2020-08-28 12:37:1827f491d8699691693a49de0311f599217421a625d6887ef3ed28eab01a99d311docHeodo
2020-08-28 12:19:16c2f7b76586b0956f683f1a66fb3827a69a3daf0166e097cc1b0571adece3aed4docHeodo
2020-08-28 11:57:06c4cda086323512134f845db4fcbec97b3eef21782d3378e21ed8e054886dc2ecdocHeodo