URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: mamaspresence.com
Domain registrar:GoDaddy -
Domain registration date:2016-07-21 15:34:11 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-20 14:55:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-26 15:34:06 13.248.213.45a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-07-26 15:34:06 76.223.67.189a67c48129651a0940.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2022-01-20 14:55:05 52.70.16.218ec2-52-70-16-218.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-20 14:55:15http://mamaspresence.com/cgi-bin/OI_28817/Offlineemotet ext epoch5 redir-doc xls Cryptolaemus1
2022-01-20 14:55:05http://mamaspresence.com/cgi-bin/OI_28817/?i=1Offlinedoc emotet ext epoch5 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-20 22:47:47200e8f491dade178eca83bd109426425ffe7ca9d4baf974a204e3835c56ceb2exlsm Heodo
2022-01-20 22:33:31aec2322328224504e216bae76697e68ec37167ececb7693615d72235044bf28fxlsmHeodo
2022-01-20 21:58:1546dadb348869cda14d38466d791ebf6c906f5ec26cc305fdca50921785f48b20xlsm Heodo
2022-01-20 21:30:466b010b591c50b68c8101ed6ffe62e903c6501ae17d1b430a904288c1391d4482xlsm Heodo
2022-01-20 21:19:475eb512924e585833ee9f0111efd74c3e3ced26d8a78db2b71d87bb6c9f684791xlsm Heodo
2022-01-20 20:43:00f3af1bae6675bb7eff796079a60c5a67ec86892f1c09053d2c25fe7d9fcee836xlsm Heodo
2022-01-20 20:16:54b1551887350e6e3d73f1d159a97f121cdb3d5b3d9f151de703c313f247958248xlsm Heodo
2022-01-20 19:49:45f3f1542a86bb2d668046714e3987278506d3308023b1cb398efa9573d2da7776xlsm Heodo
2022-01-20 19:27:201bccdaed8a9d03e7c5a5f0ecd9ca25e942077d1be538087e6451cc3030e37b8dxlsm Heodo
2022-01-20 19:00:257429c9e25f9d5b509f78af97a0f595fac9ce8122ad4788c17087360e06521b2fxlsm Heodo
2022-01-20 18:33:55f48ce531d75c5080dd92c721b92678a75a2be77b9c53d1a33d5539c695d1e614xlsm Heodo
2022-01-20 18:17:218ca261137fec414bb9066e12a3b88f3872e87a71d57134c1ee8331a7c0590965xlsm Heodo
2022-01-20 17:44:5547b55d5918804812bdc25923b93b4d42f3f5fb005f755266aba09ace6d636e20xlsmHeodo
2022-01-20 17:26:1054dd7b43faf6af4521533712663354a19b6793199ff1fd6b355828448b1cce66xlsm Heodo
2022-01-20 16:57:027805fd902552d2c362cec5d35c3ab11be2ecd01d5932757e4f175b5f9d21ba1fxlsm Heodo
2022-01-20 16:38:122ef3416e562bce54a825d048a989566f6f14e3f396d453e6efab5664d6066b3bxlsm Heodo
2022-01-20 16:25:47619c3ee3590e414b2de3333ff07b4cb2df3c76fc7512468d4a6499833db70078xlsm Heodo
2022-01-20 16:15:15d3f4d5fc34a444c8ae251c04b1e12ad1371e72f9f7f5682c02e0339eb3fb6ba8xlsm Heodo
2022-01-20 16:01:23dd2013ad0148de7b9a7877b7b27f3372c04615fb214c98f8a96d3d5dc80b03f5xlsm Heodo
2022-01-20 15:46:079761bc5de47973837988a9be7b5128db72f1817d53c224709b5b2c63848e47ddxlsm Heodo
2022-01-20 15:25:5717fec23004233b510f24a66fbfbff83304bf565e4138fa85b44c7b80d9dfcbafxlsm Heodo
2022-01-20 15:15:22bc7476f9d9148b939127a2024a1b341cec82fb398bf06667bdd3da4b1acc8bd2xlsm Heodo
2022-01-20 14:55:15481317b25ea183c9c378579bfaf8bef4411ac2f8fdf112f34b1db080693304d1html  
2022-01-20 14:55:05d13c581258a7b7cea4c550025cf6e9a52d509d4759d34753a8386e339153ef11xlsm Heodo