URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: fabshield.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-01-29 17:23:04 UTC
Total malware sites :1
A record(s) observed :16

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-09 15:52:38 13.223.25.84ec2-13-223-25-84.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes
2025-08-09 15:52:38 54.243.117.197ec2-54-243-117-197.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes
2025-05-26 22:20:21 13.216.111.180ec2-13-216-111-180.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-04-29 23:21:30 3.18.7.81ec2-3-18-7-81.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-04-29 23:21:30 3.19.116.195ec2-3-19-116-195.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-04-27 15:53:45 34.205.242.146ec2-34-205-242-146.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-04-27 15:53:45 54.161.222.85ec2-54-161-222-85.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-05-05 02:50:04 3.130.204.160ec2-3-130-204-160.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-05-05 02:50:04 3.130.253.23ec2-3-130-253-23.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-05-02 12:37:40 18.119.154.66ec2-18-119-154-66.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-01-29 17:23:05https://fabshield.com/wp-admin/Overview/349s8wq...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-01-31 05:56:09490e43ebe2e9f9222605d29f2786989ecbefca72897bd9b172d3e893dc3a2493docxHeodo
2020-01-31 04:40:09b2b0dc6852bea40e3dd6253292876a67f820441f13e9da1c5e2f415654694f89docx  
2020-01-31 04:05:519c5de271d65d0f60677c42eca0d3ef7644017fbeb235ebf84a1bf90f0759e3d8docx  
2020-01-31 03:15:196971378f1c7eccd93a6ab7cf3dd5ea551a5ca14cf564e121f883c2f364e46876docx  
2020-01-31 01:45:214e2b359f6af536b5b64747340cafc480a9ca13749929b951a2db7d5f18b00facdocx  
2020-01-31 00:45:16757a48d02b6fe0b6727f63c17977c6b7dade46c23a91bd48a77efce02b1619b7docx Heodo
2020-01-30 23:30:5854e129e6834af97b4ad21f3e8157eec8f08d3c46c4c49680d1b9a539429f58f5doc  
2020-01-30 22:03:0576483b424ad76c877f0c7f4e62405edc7e07a17978fcfb4c2b9087196d568a1cdocx Heodo
2020-01-30 21:18:379d7903dcb84d56c7bb6712b573683c2ef0302a29123305fedbf29279c6e9815cdocx Heodo
2020-01-30 20:35:16c7710490083776e7b352f36bc4922c56479b54e76458d8d20a85be4f7b4af7a7docx Heodo
2020-01-30 19:04:001b5d6a9fe7a562d4d940efb272ceb962dda14a0cb672a089fe2a0ed20585c0a0docx Heodo
2020-01-30 18:28:59643bbf34d9e019017fc813de23d9d7b7d1e622e67679b779a60a3de0153f7ab7doc  
2020-01-30 17:45:452a4836acbc4c134aaea56cb543461fc151e8db768f9cf1a3edb70813dff8327adoc Heodo
2020-01-30 16:35:22cc7d8ba3bc76b203da5c3994f672d0a3d03d98fcf9e5a8913db8535608bb7f9fdocx  
2020-01-30 15:38:390f306bd8f9966cbd586c596b54c32f00c23bf48963ef3a0158e1faa3ca1add83doc  
2020-01-30 15:03:36bcaa904b499b15bb8bdfd3594adbb8792a1f6d6c0719df8c754ae70d5e01d1afdoc  
2020-01-30 13:49:506503eeb82c3bc74d74c8bd056d2737b539afd23333ae2f25ec18b2ba72a6c567doc Heodo
2020-01-30 12:20:140e8bf4227a4711a00bdef9eecc715129b94f89647c1606b0826974f91b00c90bdoc Heodo
2020-01-29 17:23:05135e6e64bd7742b372ada6b825319eb55fa6081a563f2bb5b8c41b146badb7e9docHeodo