URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: luxuryamir.com
Domain registrar:Alibaba -
Domain registration date:2021-03-31 14:42:39 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-20 20:59:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-01 19:30:10 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2022-01-21 11:31:17 104.21.78.39Not listedAS13335 CLOUDFLARENETn/ano
2022-01-21 11:31:14 172.67.215.189Not listedAS13335 CLOUDFLARENETn/ano
2022-01-20 20:59:05 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2022-01-20 20:59:05 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2022-02-02 10:45:13 188.114.96.12SBL687667AS13335 CLOUDFLARENETn/ano
2022-02-02 10:45:14 188.114.97.12SBL687666AS13335 CLOUDFLARENETn/ano
2022-01-20 21:09:46 188.114.96.15Not listedAS13335 CLOUDFLARENETn/ano
2022-01-20 21:09:47 188.114.97.15Not listedAS13335 CLOUDFLARENETn/ano
2022-01-25 21:49:28 188.114.96.19Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-20 20:59:05https://luxuryamir.com/ry8e7l/hmD_67/Offlineemotet ext epoch5 redir-doc xls Cryptolaemus1
2022-01-20 20:59:05https://luxuryamir.com/ry8e7l/hmD_67/?i=1Offlinedoc emotet ext epoch5 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-21 11:09:1664c6ba33444e5db3cc9c99613d04fd163ec1971ee5eb90041a17068e37578fc0xlsHeodo
2022-01-21 10:29:35b0e9d2148a1c5ad60a5ccbc0c8b753f7c81e298cac18059db3c3ed66a04d4068xls Heodo
2022-01-21 08:39:424170fd2e1e20be004dc4fb1490bd16ce9bd092ec9d1048e6ac0a63d10c7ba255xlsm Heodo
2022-01-21 07:58:219bb2ebea9b5a85ffd22e2f2f97a07e9367ddc5ddcaa086c8903c57212273548bxlsm Heodo
2022-01-21 07:37:09df43427d915757b0932c26b7029a6f1bd5602383b04d075ce0ad95f40b1c2e19xlsm Heodo
2022-01-21 07:22:01f7f344862e543ce22b540ef4bbab44ac1dbd786c224550cb5ecbee3380403ab7xlsm Heodo
2022-01-21 06:53:22eee95e3bcd72a2d0932acc8c6e46e6b0a4d95a39ab028da3b0c11e294e0faa89xlsm Heodo
2022-01-21 06:41:13733af54ba0a2878f86abc471d5388ac61f838211959a4444ca6307819c4860d7xlsm Heodo
2022-01-21 06:09:506b4e80411216eff0629dfc0ce6788afc2578e22f48613a0664edb46f621d746axlsm Heodo
2022-01-21 05:31:384765164204e734a59822149f062f898117d41dbbb26a969800d8fc36e80a9a49xlsm Heodo
2022-01-21 04:57:288293affd245bca747939f06a07970c40d349524f0e57a8037bbb78d7b6d04263xlsm Heodo
2022-01-21 04:42:568b6c3d1c1c4f0194ac14f20217620719ae9888660cfc5b07fdc42970e6fd377exlsm Heodo
2022-01-21 04:10:0379d21212ede80612cecd2e319424918b3f95dd07e305e99bb3f4941ab60ff2c4xlsm Heodo
2022-01-21 03:45:13655e69dfaf74c3a34eb02d75f4e51264009fbdbe46a7f535b9e72888bffeaf58xlsm Heodo
2022-01-21 03:05:225e0d6d63ac743de0bb942f5367315786752d13884fc04124a4b8f577a3f8bca9xlsm Heodo
2022-01-21 02:34:0219b1cb4bcc5006f6fe58960a449aa850117383b7e330f8e58035510f3be23149xlsm Heodo
2022-01-21 02:04:33c21af06b5a5f866a493669336f0c0d2d4d981faeab18708879be631c5b4f3c55xlsm Heodo
2022-01-21 01:39:5372053ec5fe9ba65c857235179e8529eec75c3aba924b386ecf41b34729d0935bxlsm Heodo
2022-01-21 01:21:298a12bb899a8c477155c5aae284050416300acb42d4b3c7da672f8e12bdee8ec4xlsm Heodo
2022-01-21 01:11:550f5d70d653951694aacfdbae441a87340e2689247cc1dc79852a86d5c8e7dd2bxlsm Heodo
2022-01-21 00:22:17aa778c3fafe2327bc81ba1c4963a5ee8354aeb750a96e8ce5f4d0392df3ddd4axlsm Heodo
2022-01-21 00:09:34442da867e6d871fad0d4e472ef48bd2ca7ac41ef601355875379056453ccf42dxlsm Heodo
2022-01-20 23:46:1797a52b68f8d7ad41ba580f95749d7d810ce3fab98d8ea92461adfee77cfa9203xlsm Heodo
2022-01-20 23:18:40782f99cf1c019d48f827fb6d29e75c842fceea0423bbddd81620697d366bfeeexlsm Heodo
2022-01-20 23:01:26200e8f491dade178eca83bd109426425ffe7ca9d4baf974a204e3835c56ceb2exlsm Heodo
2022-01-20 22:23:07aec2322328224504e216bae76697e68ec37167ececb7693615d72235044bf28fxlsmHeodo
2022-01-20 22:21:01be10fbe811ceaeb57d7f034671958a839f1f6933840540db4bfd66c8bffc4818html  
2022-01-20 21:57:4146dadb348869cda14d38466d791ebf6c906f5ec26cc305fdca50921785f48b20xlsm Heodo
2022-01-20 21:40:506b010b591c50b68c8101ed6ffe62e903c6501ae17d1b430a904288c1391d4482xlsm Heodo
2022-01-20 21:09:455eb512924e585833ee9f0111efd74c3e3ced26d8a78db2b71d87bb6c9f684791xlsm Heodo
2022-01-20 20:59:0509ad3c106e22483dfe26ae337c6de3bdef43f863417bca7d87ac21584c9ae94ehtml  
2022-01-20 20:59:05f3af1bae6675bb7eff796079a60c5a67ec86892f1c09053d2c25fe7d9fcee836xlsm Heodo