URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ehumanteam.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-07 08:10:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :16

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-26 20:44:55 44.208.83.180ec2-44-208-83-180.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-11-26 20:44:55 54.84.240.235ec2-54-84-240-235.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-10-16 06:28:56 172.233.219.123viridian02.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-16 06:28:56 172.233.219.49viridian01.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-16 06:28:56 172.233.219.78viridian03.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-16 06:28:56 172.237.146.25viridian06.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-16 06:28:56 172.237.146.38viridian04.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-16 06:28:56 172.237.146.8viridian05.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2025-10-06 13:17:43 69.16.231.60lb04.parklogic.comNot listedAS32244 LIQUIDWEB- USno
2025-08-19 02:35:31 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-18 14:22:17http://ehumanteam.com/3XtECzy2N/Reporting/mb1ge...Offlinedoc emotet ext epoch2 heodo ext spamhaus
2020-08-07 08:10:06http://ehumanteam.com/diffhotel/FILE/918gth64/p...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-09-11 16:07:51bda73c7f71bcdb668232901ffe99d07f611eb5a64d0c69b43ebbde6fb195495bunknown  
2020-08-18 15:15:430a41f0b1fa2d723ed6b405e7f8ec27f3a38956badc1df3350a581e21c8c9d203docHeodo
2020-08-18 14:57:080cef6300d4ff34161fe15685c7de03dd6663177b6ca1d87df136eb05e9daf650docHeodo
2020-08-18 14:22:1784bef696e9777c4868dddadd73f2da1bee941b1582dedb67d554ee315d0f9466docHeodo
2020-08-07 21:49:3141051e1b0ef6db0f014593da4cb56df1bd320b0b7f7917b80b0e44f529504443doc Heodo
2020-08-07 19:58:493f4c381531d4604385f763850e0e32cd72c1b21b78330327c64b2da16e62e9f8doc Heodo
2020-08-07 19:28:12274a4a43c73146474792e4027e59c62a74d50880eb7ea20bb84e40abf6df99acdoc Heodo
2020-08-07 17:56:42647e4bdd2ba51f7dfc1c7749092db78d95b64ca550d266e025602d2437cb503ddoc Heodo
2020-08-07 14:52:35268e2665f9d43c891185ecba8417dc09662221c10d272438aa890998da163022doc Heodo
2020-08-07 14:22:058b8e47ea740122d956b050a9ae147e3fed0f577bb4807b577fc5e491a0d3a045doc Heodo
2020-08-07 14:03:53c5073d635a11aa6e28f69926c0a499058a39d8a76e9ecafbf2933c03af8fca47doc Heodo
2020-08-07 11:55:00cede25e4801348361a934627a1928932140f56021e2f05723e90924a37a2501cdocHeodo
2020-08-07 09:42:2612cf7f0354a11a74100012078b6e2be1acdf8afe94c595d339fb0eabf973accfdoc Heodo
2020-08-07 09:21:01848159e2d023ddbb3136a1a30ae91e9dad7900c86b3efd66d8670436e9bbea95doc Heodo
2020-08-07 08:10:06af720571420bce910e598f476be4753939fd4348f0a9e6eb8b1484b2a51881c8doc Heodo