URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: investmenthub.world
Domain registrar:Namecheap -
Domain registration date:2021-10-27 14:38:55 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-08 22:11:08 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-23 15:18:33 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-10-23 15:18:33 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2022-10-27 21:15:46 99.83.154.118a51062ecadbb5a26e.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-12-09 19:18:17 162.55.190.232static.232.190.55.162.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno
2021-12-08 22:11:09 172.67.207.158Not listedAS13335 CLOUDFLARENETn/ano
2021-12-08 22:11:09 104.21.93.84Not listedAS13335 CLOUDFLARENETn/ano
2025-11-07 09:01:19 104.21.3.20Not listedAS13335 CLOUDFLARENETn/ano
2025-11-07 09:01:19 172.67.130.12Not listedAS13335 CLOUDFLARENETn/ano
2025-10-21 04:58:51 199.59.243.228Not listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-08 22:11:09http://investmenthub.world/shopkeepery/UGXiOMBT...Offlinedoc emotet ext epoch4 heodo ext waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-09 06:34:410d93a4f12d6e52dd86f8194dc522bdf7b6c4724898e929e12943c15cef4f3aa9xlsmHeodo
2021-12-09 02:46:2627eb195a0ed6e64b5b3a50fd111ddd216fd6545a3b74891745c72970cad9035fxlsmHeodo
2021-12-09 02:18:0172ddbbd658380e1eaca1deaf8a20ceaf53947f3f549ce84d05b3906cb13d04eexlsm Heodo
2021-12-09 02:08:19957f0fab563de48ae41da020061dc0090e02cf4eaf0b022344a742105a53be99xlsm Heodo
2021-12-09 01:39:184fb3b7dfdd32dcb5f30ce1f30529aaee5a53032f3edaeaebffec25390594a57cxlsm Heodo
2021-12-09 01:03:593f69c247692ec5db4d7bcc92ebabc9bad455e0a32f0a2d7bc3a247000cc634c7xlsm Heodo
2021-12-09 00:44:33f008cd221bbf64a6901e9e67baba0f4e5c28d6f0e30e06617c8555799ba3f17cxlsm Heodo
2021-12-09 00:28:3147eb41ba61a62ac3714f2a4f994111c1e7954a2c79ab44eeb784863b2eb9c67exlsm Heodo
2021-12-09 00:16:3459f510c09d494784d0266b6f5c9963b2b47590db031468749c07714441bd480axlsm Heodo
2021-12-08 23:44:531438301d4dcd00de6de8ccb86b00e75b7f593f2ace4b8fd843c5573d4bffba2exlsm Heodo
2021-12-08 23:30:308510a0ab3226501a044e1cc7caa1f0b23c752017b2bf7525f339f5e35bb91f96xlsm Heodo
2021-12-08 23:16:28736ccd4db67873fe036199ce7eaba8d2634f53a7b78c6ad371dff2f968d7c7d2xlsm Heodo
2021-12-08 22:43:00cf6930d68abc28dbe2b1177db781ba6320a7a2499da4cb80156d61127dde6b8cxlsm Heodo
2021-12-08 22:29:45e5ede3165bf98efcd9d310d5d4f49782de35de80d07de2046912f3a3741424b0xlsm Heodo
2021-12-08 22:11:09d36dea9571b31b8db6a31b4e95e972b5ec34b724167fd0e647479a7331a59cccxlsm Heodo