URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: haobay.online
Domain registrar:GoDaddy -
Domain registration date:2021-12-14 07:51:56 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 18:45:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-11 18:45:05 162.214.243.166162-214-243-166.unifiedlayer.comNot listedAS46606 UNIFIEDLAYER-AS-1- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 18:45:05https://haobay.online/b/QLdpd/Offlineemotet ext epoch4 redir-doc xls waga_tw
2022-01-11 18:45:05https://haobay.online/b/QLdpd/?i=1Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 01:56:37d70eea3a457a572c1ee00b87e0c62ad39c9a8307340a7bff3bae0a08ade7c556xlsSilentBuilder
2022-01-12 01:29:37532105c51f0f4b68350191b68f17d6226112e97f273af215511a517604a1770exlsSilentBuilder
2022-01-12 00:58:231b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bxls SilentBuilder
2022-01-12 00:33:28f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feeaxls SilentBuilder
2022-01-12 00:03:021bd3d0d3bef771b182e3de5670d6f9515c73b76cf971203cccba88fb2dd3ddbbxlsSilentBuilder
2022-01-11 23:47:345dd8cf32347063a7b6b80c824526d1f58a3b8c99344eaea74dad15d687395f64xlsSilentBuilder
2022-01-11 23:22:17bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8xlsSilentBuilder
2022-01-11 23:07:435c5fd037c414e33a6538da72a5ea4ae89c8dac15b396b6a10e8504a0b5a7ee75xlsHeodo
2022-01-11 22:43:41e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091xlsHeodo
2022-01-11 22:16:5415808d5cf09ee4a60ed9e18d0b403cd762cbf7613246e2cdfa6fba88eb654dd8xlsSilentBuilder
2022-01-11 21:42:41e7065618e785e98792d570656fd412ecf695c45ec5a8123d04cf4ee302d225bfxlsSilentBuilder
2022-01-11 21:28:449ade9daf48cb63c929cd8e7ec03ac77ed41d362efaa79453d0eda4553747c404xlsSilentBuilder
2022-01-11 21:16:13c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7xls Heodo
2022-01-11 20:44:29416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dxlsSilentBuilder
2022-01-11 20:17:19d92b0ebb1f64086c8c4d5b238f3683a3319bcf041cdfc9e6736f742a260a5ce2xlsSilentBuilder
2022-01-11 19:54:28fe48432635e691df0782c8195559f80acd38518a812ec1ea5fc96957d94f6642xlsSilentBuilder
2022-01-11 19:35:3424160ff88a8c4ee8d12c4cad09dbd7e744c2bf1bfd24b636cb436cb047d3324dxlsSilentBuilder
2022-01-11 19:20:38e9a7a09bdacc562bedc71638c17bacb72b445281366d192033d7c8c85f83ce7fxls SilentBuilder
2022-01-11 18:45:0560c8098b2b7bf07470e509e5ae509c51dbba6edbdd2e8bd21bb696d7798a9535html  
2022-01-11 18:45:05ff921982c20accb17e884e46eaec7fc5b464fadfc7b000e5ae39fb1659fe576exls SilentBuilder