URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: hexagon-hotel.loyalty.com.hk
Domain registrar: n/a
Domain registration date:2005-02-17 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-11-17 09:36:06 UTC
Total malware sites :1
A record(s) observed :231

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-11-27 10:29:22 13.250.30.94ec2-13-250-30-94.ap-southeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- SGyes
2021-11-24 22:26:49 18.169.124.243ec2-18-169-124-243.eu-west-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- GBno
2021-11-18 14:49:17 108.139.210.110server-108-139-210-110.fco50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:49:19 108.139.210.24server-108-139-210-24.fco50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:49:15 108.139.210.68server-108-139-210-68.fco50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:49:20 108.139.210.72server-108-139-210-72.fco50.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:15:49 13.32.214.106server-13-32-214-106.atl56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:15:49 13.32.214.89server-13-32-214-89.atl56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:15:48 13.32.214.9server-13-32-214-9.atl56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2021-11-18 14:15:50 13.32.214.94server-13-32-214-94.atl56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-11-17 09:36:14http://hexagon-hotel.loyalty.com.hk/wp-includes...Offlinedoc emotet ext epoch4 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-11-17 09:36:1306012c700c1dac4c122303e920fdf1c71c41e681673c241c9698e5766df275a8docmHeodo