URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-01 11:50:03 | 45.156.250.99 | neutron.global.ba | Not listed | AS200698 GLOBALHOST-BOSNIA-AS | BA | yes |
| 2020-07-28 06:28:04 | 94.130.129.55 | static.55.129.130.94.clients.your-server.de | Not listed | AS24940 HETZNER-AS | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-07-28 06:28:04 | http://megaplast.ba/wp-admin/u4z-jb-41/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-08-06 18:34:21 | 5a5dc20bcd019b0ac67a80f0eb70ec331c16dae156b9990db0a3e6f2907238dd | doc | Heodo | |
| 2020-07-28 08:07:25 | 4fc696232ad4c1214d2b3d17bcf0f268ddab6901590133a86284fd475bffc038 | doc | Heodo | |
| 2020-07-28 07:52:40 | 35f182246a6245227b09f3f93802700efb8a0ca75d89922a7f8ec04f38d1ba05 | doc | Heodo | |
| 2020-07-28 07:35:50 | 9850f2cd940043ac7adb6b01af7095aa95a510c7b363a69dbc6eaab8b44c2444 | doc | Heodo | |
| 2020-07-28 07:18:09 | a644b61aea4e67fa295d3966ece9fd43e79e99047dd804a9d2e2e538c0711071 | doc | Heodo | |
| 2020-07-28 06:28:04 | d652244433caaa17c36aac28e633467530b4f4405da4280dc2ce54de0cee1f96 | doc | Heodo |
BA
DE