URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: euob.youstarsbuilding.com
Domain registrar:Amazon -
Domain registration date:2022-08-01 14:43:58 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-12-25 14:26:07 UTC
Total malware sites :2
Online malware sites :2 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2025-12-30 09:49:06 UTC
Oldest active malware site :2025-12-25 14:26:09 UTC (Age: 5 months, 3 days, 8 hours, 44 minutes)
A record(s) observed :20

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-25 14:26:09 13.35.58.37server-13-35-58-37.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-12-25 14:26:09 13.35.58.81server-13-35-58-81.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-12-25 14:26:09 13.35.58.124server-13-35-58-124.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-12-25 14:26:09 13.35.58.44server-13-35-58-44.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2026-02-05 03:07:25 18.239.18.10server-18-239-18-10.ams58.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2026-02-05 03:07:25 18.239.18.13server-18-239-18-13.ams58.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2026-02-05 03:07:25 18.239.18.68server-18-239-18-68.ams58.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2026-02-05 03:07:25 18.239.18.76server-18-239-18-76.ams58.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2026-04-14 19:44:02 108.157.150.106server-108-157-150-106.mci50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2026-04-14 19:44:02 108.157.150.35server-108-157-150-35.mci50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-30 09:49:06http://euob.youstarsbuilding.com/sxp/i/522f8dba...Online JAMESWT_WT
2025-12-25 14:26:09https://euob.youstarsbuilding.com/sxp/i/522f8db...Online abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-27 18:21:12c05081da297d2d221e87a65fec2b05c7de47d5e61ce57a56d3db3a3275776c30unknown  
2026-04-27 17:53:16c05081da297d2d221e87a65fec2b05c7de47d5e61ce57a56d3db3a3275776c30unknown  
2026-04-15 17:46:3106bd12f30c464c8b2e20b98d41f56c286495822d6e53ec56c10e8909666dde13unknown  
2026-04-15 16:19:4606bd12f30c464c8b2e20b98d41f56c286495822d6e53ec56c10e8909666dde13unknown  
2026-03-15 20:44:06831e1209df4e78692c616098a4000e550a253ca64972907db18dada476bb966bunknown  
2026-03-15 17:35:35831e1209df4e78692c616098a4000e550a253ca64972907db18dada476bb966bunknown  
2026-03-08 17:44:334d206f23dfad6214675af947d5847f7120ef1b3a6a4378a7785679e77bf0efccunknown  
2026-03-08 16:53:454d206f23dfad6214675af947d5847f7120ef1b3a6a4378a7785679e77bf0efccunknown  
2026-03-01 20:40:391bfabbc3f61d4a53ce7b2e5a22a5728b8e2a9f345c71eeabd7dcffef082a1729unknown  
2026-03-01 19:41:251bfabbc3f61d4a53ce7b2e5a22a5728b8e2a9f345c71eeabd7dcffef082a1729unknown  
2026-02-23 01:53:2287525c2726e884becd96d5a6ee0c8c2e66e382d4ab0f6dfb896e9ea0bbffe834unknown  
2026-02-23 01:51:5387525c2726e884becd96d5a6ee0c8c2e66e382d4ab0f6dfb896e9ea0bbffe834unknown  
2026-02-18 17:16:247e85fe05518bfaa5f4ae7f217e26b443034cc0e50b0a532d54d1ba7a5a4474b6unknown  
2026-02-18 15:55:367e85fe05518bfaa5f4ae7f217e26b443034cc0e50b0a532d54d1ba7a5a4474b6unknown  
2026-02-17 18:48:3867f597109e003ba1fe22b67e6ecc5fc0cc913655509f6ba7b67ae5579a252d71unknown  
2026-02-17 17:23:2267f597109e003ba1fe22b67e6ecc5fc0cc913655509f6ba7b67ae5579a252d71unknown  
2026-01-07 18:36:1204e95fb2bce0865767f340074a2d6f08b679baea04128be9e3bd12591e4634b5unknown  
2026-01-07 17:44:0904e95fb2bce0865767f340074a2d6f08b679baea04128be9e3bd12591e4634b5unknown  
2025-12-30 09:49:06fa5003d12c1bfbab92fa2f6f60fe08e3d3a3ebdd283cf071b22231d69338f2abunknown  
2025-12-25 14:26:09fa5003d12c1bfbab92fa2f6f60fe08e3d3a3ebdd283cf071b22231d69338f2abunknown