URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 11:05:42 | 184.168.107.207 | 207.107.168.184.host.secureserver.net | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | SG | yes |
| 2023-05-17 13:06:27 | 68.178.224.210 | 210.224.178.68.host.secureserver.net | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | US | no |
| 2023-09-02 12:08:22 | 104.207.134.116 | phoenix.herosite.pro | Not listed | AS20473 AS-VULTR | US | no |
| 2023-07-13 14:55:18 | 103.212.121.57 | flash.herosite.pro | Not listed | AS135222 MWNASHIK-AS | IN | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2023-06-16 15:24:34 | https://globalhse.org/ietu/?1 | Offline | BB32 geofenced js Qakbot | |
| 2023-06-15 16:14:48 | https://globalhse.org/ie/?1 | Offline | BB32 geofenced js Qakbot | |
| 2023-06-14 12:32:40 | https://globalhse.org/entu/?1 | Offline | BB32 geofenced js Qakbot | |
| 2023-05-17 13:06:27 | https://globalhse.org/qaf/?1 | Offline | BB28 geofenced js Qakbot |
The table below shows recent payloads delivery by this host.

SG
IN