URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-29 21:52:14 | 185.104.29.154 | web0159.zxcs.nl | Not listed | AS206281 AS-ZXCS | NL | yes |
| 2020-08-28 20:55:06 | 145.131.16.50 | arg-pldacl11.amsiohosting.net | Not listed | AS48635 CLDIN-NL | NL | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-08-28 20:55:06 | http://kleuropkleur.nl/Media/lm/m4ai31712075561... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-09-01 08:07:26 | 81d8e45cbeaead2f526b43b2b03f084b349ad5b43d6af0669c31143ca394341f | doc | Heodo | |
| 2020-09-01 04:57:01 | e2353bdbd1f317239d51497879c09ff20b0d15e4bf7da3a599295293e5b4451b | doc | ||
| 2020-08-29 14:06:54 | ab465edf58b50037bd4c7da09e85cf87e5a83e9301a3b75a761b682142dfdfd0 | doc | Heodo | |
| 2020-08-29 13:44:56 | 7bb6a59e90701bb2af8a195fe877681d0446710c6001ce3b05e2e87ac4860d37 | doc | Heodo | |
| 2020-08-28 23:34:05 | f5d308b615528818047b9010074fd219d6248ce43aff167bcc0bbb56a6d45504 | doc | Heodo | |
| 2020-08-28 22:48:49 | 3e8f3a7d0d0ce8e8ab7b5363b9c12f3219bd75974ac09118344ccc9c2b727727 | doc | Heodo | |
| 2020-08-28 20:55:06 | e5cbe16ff82c0a8778906a889f99a6cc41def9921e1944cf107eab74e277559b | doc | Heodo |
NL