URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: haball.pk
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-30 20:02:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-01 10:15:26 104.26.4.228Not listedAS13335 CLOUDFLARENETn/ayes
2025-05-01 10:15:26 104.26.5.228Not listedAS13335 CLOUDFLARENETn/ayes
2025-05-01 10:15:26 172.67.73.120Not listedAS13335 CLOUDFLARENETn/ayes
2023-07-04 11:48:30 104.26.14.100Not listedAS13335 CLOUDFLARENETn/ano
2023-07-04 11:48:30 104.26.15.100Not listedAS13335 CLOUDFLARENETn/ano
2023-07-04 11:48:31 172.67.70.156Not listedAS13335 CLOUDFLARENETn/ano
2022-07-26 19:52:25 95.111.239.188ns0107.hostingcare.netNot listedAS51167 CONTABO- FRno
2022-07-30 15:35:33 104.21.54.128Not listedAS13335 CLOUDFLARENETn/ano
2022-07-30 15:35:33 172.67.138.180Not listedAS13335 CLOUDFLARENETn/ano
2022-09-24 08:39:06 188.114.96.5Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-30 20:10:05https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr...Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1
2022-03-30 20:02:08https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr56/Offlineemotet ext epoch4 heodo ext redir-doc SilentBuilder xls Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-31 06:40:1565320942312ee91e071ae3e59670ffc7c8f0f691fcf70cfebdf8bf25631a9e21xlsm Heodo
2022-03-31 05:48:2365320942312ee91e071ae3e59670ffc7c8f0f691fcf70cfebdf8bf25631a9e21xlsm Heodo
2022-03-31 05:40:33566c3447fd5a1b7f7f0c942d484a0185bcd747d47f9c487452dcbfed1979bd52xlsm Heodo
2022-03-31 04:25:1696fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51xlsm Heodo
2022-03-31 03:48:0530deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fxlsm Heodo
2022-03-31 03:29:32484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77xlsm Heodo
2022-03-31 03:14:42265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bxlsm Heodo
2022-03-31 02:47:55a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dxlsm Heodo
2022-03-31 01:58:5052f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66xlsm Heodo
2022-03-31 01:57:1052f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66xlsm Heodo
2022-03-31 01:35:5570c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080xlsm Heodo
2022-03-31 01:26:350c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3xlsm Heodo
2022-03-31 00:32:02b73f04d9f7a2ce5624249871b7f1277fcc2959bfe5abcaa33e1da19e0da9cb08xlsm Heodo
2022-03-31 00:08:1408e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baxlsm Heodo
2022-03-30 23:44:099a0b2121a81929d3ea98a8b4b0e20693192eabb5c4081e2ac411fe4ed06f9f7bxlsm Heodo
2022-03-30 23:18:462909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddxlsm Heodo
2022-03-30 22:45:0251be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cxlsm Heodo
2022-03-30 22:31:0351be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cxlsm Heodo
2022-03-30 21:58:25a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554xlsm Heodo
2022-03-30 21:52:53b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03xlsm Heodo
2022-03-30 21:38:432fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58xls SilentBuilder
2022-03-30 21:15:1134c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4xlsSilentBuilder
2022-03-30 20:10:057324fd5254825996acb024055b8f85c89b19897ef327543836bad401b074d0b6xls SilentBuilder
2022-03-30 20:02:073cbbf9a615d5ba920d7594a8940ee11c48695f2191047be122c47067cc0ee9d7html