URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: goodfellas.me
Domain registrar:GoDaddy -
Domain registration date:2020-03-03 20:03:05 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-13 00:52:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 03:54:22 185.230.63.107unalocated.63.wixsite.comNot listedAS58182 wix_com- USyes
2025-04-28 03:54:22 185.230.63.171unalocated.63.wixsite.comNot listedAS58182 wix_com- USyes
2025-04-28 03:54:22 185.230.63.186unalocated.63.wixsite.comNot listedAS58182 wix_com- USyes
2022-01-13 00:52:17 79.142.73.145s15.dukahosting.comNot listedAS51430 ALTUS- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-13 00:52:17https://goodfellas.me/content/74475874-5200816/Offlineemotet ext epoch5 redir-doc xls sugimu_sec
2022-01-13 00:52:17https://goodfellas.me/content/74475874-5200816/...Offlinedoc emotet ext epoch5 heodo ext sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-13 14:04:19109868bbf981851bac44548c11bee90f08fd3c83e06c9b9539f568e047f45e0axlsm Heodo
2022-01-13 13:23:39399fd8ce9218a6b24bbf3c9e307934df9b2954d45119371365be1360c88ec6f5xlsm Heodo
2022-01-13 12:11:101837567c1c4771488aaff8602f2c98711463d9afd7dbe2a3ab3413e37e30f610xlsm Heodo
2022-01-13 11:40:12cd1b8b06a27b93f21a8da161ab4af2768ecdcbe5f8f5122d89c33caf145da46cxlsm  
2022-01-13 10:46:24726be01c1600c33b9a3d322885ca12383ec5b64546bb389670176f77f7faf162xlsm Heodo
2022-01-13 07:31:1127142990970a1968021bca00b4005ef206e3a553179b2e717e82ebfe8a8af1b9xlsm Heodo
2022-01-13 06:50:1249ec26f8a352003e43a32615495ae4554e0bb8485ef889e7ba57cf869f026c4cxlsm Heodo
2022-01-13 06:42:29259272a5032f537239c61ba1c8b5bdd26e8e6c4f1ec9b54ee52eaeeac5f5690cxlsm Heodo
2022-01-13 05:39:309eb7d16794f6e4e2e701458af298b2b16c91a04dd45361cc306f32bc5fd25491xlsm Heodo
2022-01-13 04:46:0032d200a99b9495fe0dfcab75190eb5fcb348e6fa879763d132c924fe25bfc799xlsm Heodo
2022-01-13 04:15:28cffc89330574a0b7d5096c64bff0483e4dbc38d09be06dd3fd4cafca0a4e99edxlsm Heodo
2022-01-13 03:56:09876844b7e19d8b57429b07b92fd1092f3847f3e2521cb00e52b9a418fab8b6a1xlsm Heodo
2022-01-13 03:22:35d9d0e65da97a353a9cc189af41082ae0bf1dff0acb39bb620a34ddb0c642ac79xlsmHeodo
2022-01-13 03:15:2669af6706b85f8b7530add4d0277acf97e3f30aa8240e27adf3c97ba52581e86cxlsm Heodo
2022-01-13 02:25:477d631c017cb37c772f9ec3a267d89dc26eb44eaf38e4fc579d90bf739878c8f2xlsm Heodo
2022-01-13 01:56:58638c333549cd204d298c9443eb29055edf4bc9e420895fa088aef37f7b2668fexlsm Heodo
2022-01-13 01:34:341fc7f3374c25268b7040c919649cff96394322307f0b9156431e2200d78bba77xlsm Heodo
2022-01-13 01:13:58cb57d02722993dd10fe56d30e2b0675417684cdc6308212c9e30035f95e257ddxlsm Heodo
2022-01-13 01:07:5174d5c7f7b4fb4055de51780c051eff8592ac706105ecb6852dc5100690910f2ehtml