URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gaiarllc.com
Domain registrar:GMO Internet -
Domain registration date:2018-02-22 07:04:41 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-24 01:06:09 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-26 10:19:19 34.254.1.203ec2-34-254-1-203.eu-west-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- IEno
2021-12-24 01:06:11 157.7.44.240users203.vip.heteml.jpNot listedAS7506 MAINT-JPNIC- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-12 00:42:08http://gaiarllc.com/cache/Q_8570/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1
2022-01-12 00:42:05http://gaiarllc.com/cache/Q_8570/Offlineemotet ext epoch4 redir-doc xls waga_tw
2021-12-24 01:06:11http://gaiarllc.com/cache/thgS8VM5E39/Offlineemotet ext epoch4 redir-doc xls waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 16:49:18aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdxlsHeodo
2022-01-12 01:18:04926c822e2c4d78b252f788d3fa75a77bfed1380ad50cdacf21f3efddf15b0b26xlsSilentBuilder
2022-01-12 01:00:369d277bf6e9b937c6b9d79db16b78f65ef5346b79c5c68fd3fda71a4e18171fe7xls SilentBuilder
2022-01-12 00:42:08f7d338277f13461262faa21c960479146f4261acc6efe564964f5cd0370afd6exls SilentBuilder
2022-01-12 00:42:05f18d647885d1c7ded726735f66883d9edfb264cf2c5292869d151d157177d60fhtml  
2021-12-25 01:00:146d86065257637f41f4c2386499c1897595b93d0ada37f353c3315aba6fd85d52html  
2021-12-25 00:27:50312a886bc23e582b22381c48be12784437ad8c1fe611b3e67ef04f09c47e6f28html  
2021-12-24 23:35:05f7c70f691eb09646d73a3a993885e15f1f6bd1b2c668eb71115fb6b5dbcca01chtml  
2021-12-24 19:33:500a3275de07c06a1017989c53a3984d1996ba28ef41b4f3617bf30dfdd6183dc3html  
2021-12-24 19:06:087c3ce64d084506022a50ec3eed03e0a80908d455095bc42fc9c6d589ddc89532html  
2021-12-24 18:50:528932b1b4902e7dfdcf3339292ac6c837763f037f36e72a1ba0901eedf6635a0ehtml  
2021-12-24 17:54:039a3b0971be0ce79540c354990d634b0a855c3613d8b5498cc060d934980895dfhtml  
2021-12-24 17:04:343d8e4459a96fd3cbd38634a612da6b36d0017d179c51580f2a342969178c97fdhtml  
2021-12-24 16:39:48b4114b04715da63caceaa04c11612d3b5c4ae0bbd9c159bf9ecfae9226e7a426html  
2021-12-24 15:56:470ff3f5f08f142470808e1015a6cc548eccb40ff241534fd109c11b75d620229dhtml  
2021-12-24 14:20:34b2ab5654fa6eb6031aaf275596b7aa0421e7aa9b08a711f12fe83765eba19de0html  
2021-12-24 13:48:24d638262e1b841e339d91c0691b0eed5363f623ec8a4b266eb6bf5e694f449f2ahtml  
2021-12-24 12:55:2848229d90fd3e3a2cd0bc77ec4b69477d25e6ad6ad368180a6a2ebaaeb0451097html  
2021-12-24 12:12:44b5018d852b6f215031106c3dc8e2db8d005a6e52c2d3ffbed217386499b94e49html  
2021-12-24 10:57:1460ce3dd71672b9aafac419394c9974e0e8981a599351d7723d776146ec8f64a3html  
2021-12-24 10:31:3143cd83bdcfb70ea1d0cca2ac991505b157ac31d30ed6f7e736a388703f14079ahtml  
2021-12-24 09:38:1346679425096744e6e34fa1a6a91edb8ba4053bade6cfe3ff1c0395b5f50b6257html  
2021-12-24 09:18:4943eff0d0156168df935be5c38599e6a0ec7fe65fec5ae39dc5b7946fb67a5afahtml  
2021-12-24 05:25:3140e7b306e207ddf48180ec5cec70ba4b97b4de0cc03ab18f741d3d73f5a59a06html  
2021-12-24 04:48:07ac6b300254f829e94099d3ff9f9bfea9606de355c3f90af705845eb9ce90d938html  
2021-12-24 04:00:21295c70ebf7e252d88c159673de9184d7e359b5203c2ec9e199a294770f03ee10html  
2021-12-24 03:32:0450ff7ea169bb36603e47a015c08c47875040f416725044c8c50fa47bd32fcf0ehtml  
2021-12-24 02:42:51cfde676c6a44dbeb6d7e7b654a7670f782fc083d8e1380a0ec30a03fd6175e09html  
2021-12-24 01:55:10c986c1a602ffecfb7b786f1e81fde0cf509423bc3df93635d0524ae56a44353fhtml  
2021-12-24 01:26:411d5658c37ecd77acadfa99290a2156b2617dad816dc78bf11ee37f679ce7a5d0html  
2021-12-24 01:06:11d3aca3f16e2895f6975015e75a1da1d9d76ffd5eb72cb49a97c6ecb9def65838html