URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-12-11 10:06:53 | 99.81.215.148 | ec2-99-81-215-148.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | yes |
| 2025-12-17 05:03:58 | 52.48.198.150 | ec2-52-48-198-150.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | yes |
| 2025-11-20 12:10:20 | 52.213.111.236 | ec2-52-213-111-236.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-11-15 06:14:24 | 54.228.35.169 | ec2-54-228-35-169.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-11-11 20:49:35 | 52.214.189.141 | ec2-52-214-189-141.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-11-06 17:03:37 | 52.210.46.183 | ec2-52-210-46-183.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-11-03 20:10:41 | 54.246.90.168 | ec2-54-246-90-168.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-10-29 09:25:13 | 18.200.102.111 | ec2-18-200-102-111.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-10-24 19:35:51 | 46.137.20.217 | ec2-46-137-20-217.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
| 2025-10-21 15:38:52 | 63.33.115.234 | ec2-63-33-115-234.eu-west-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | IE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2018-08-02 15:16:07 | http://enzosystems.com/default/Rechnung/Zahlung... | Offline | doc emotet | Anonymous |
| 2018-08-01 16:10:49 | http://enzosystems.com/default/Rechnung/Zahlung... | Offline | doc emotet | |
| 2018-07-31 19:15:49 | http://enzosystems.com/DHL-Tracking/En/ | Offline | doc emotet | |
| 2018-07-27 04:04:30 | http://enzosystems.com/DHL-number/En/ | Offline | doc emotet | |
| 2018-07-25 03:57:36 | http://enzosystems.com/Jul2018/Rechnungs-Detail... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2018-08-02 17:24:06 | 0d24a0249b4a2a3fa40453f2aac7d086219f5d4f6f5a316ab857c4559d79cfb8 | doc | ||
| 2018-08-02 17:18:26 | 0d24a0249b4a2a3fa40453f2aac7d086219f5d4f6f5a316ab857c4559d79cfb8 | doc | ||
| 2018-08-01 16:10:49 | ddfa667a6805bf8b9216feb8df15b1590c340914d7142aa142ecb858d117ba9b | doc | Heodo | |
| 2018-07-25 21:36:29 | 060a0fc2dc33ae11af40e99b36563ac2b3cdbe59e7e538f1a0a0832480e8c74c | doc | Heodo |
IE