URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 18:14:46 | 208.91.197.39 | Not listed | AS40034 CONFLUENCE-NETWORK-INC | VG | yes | |
| 2022-02-08 06:52:15 | 66.175.58.9 | hostedc38.carrierzone.com | Not listed | AS30447 INFB2-AS | CA | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-02-08 06:52:15 | http://flynn-flynn.com/cgi/bdxP8s4Jbx4C/ | Offline | emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-02-09 23:27:29 | 2e5dd41a3e90e3675ceac1a504b00e35b9edafe544b29238b343a4a6f712f69c | dll | Heodo | |
| 2022-02-08 06:52:14 | f19345afb986c26291e5d1585c25d438ae0a18fc2e6ff4f9aa3f7e6fd5773ab6 | dll | Heodo |

VG
CA