URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 09:49:11 | 188.114.96.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-04-27 09:49:11 | 188.114.97.3 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-05-23 23:32:42 | 104.21.94.32 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-05-23 23:32:42 | 172.67.218.254 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2019-09-11 07:28:19 | 194.39.164.121 | 194.39.164.121.srvlist.ukfast.net | Not listed | AS61323 UKFAST | GB | no |
| 2019-07-18 07:36:26 | 188.165.239.211 | ns3014989.ip-188-165-239.eu | Not listed | AS16276 OVH | FR | no |
| 2019-05-15 08:12:05 | 87.98.219.188 | ns3284533.ip-87-98-219.eu | Not listed | AS16276 OVH | FR | no |
| 2025-11-05 05:41:02 | 188.114.96.12 | SBL687667 | AS13335 CLOUDFLARENET | n/a | no | |
| 2025-11-05 05:41:02 | 188.114.97.12 | SBL687666 | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2019-05-22 12:50:11 | http://miagoth.com/wp-content/TUBypthmA/ | Offline | emotet | |
| 2019-05-15 08:12:05 | http://miagoth.com/wp-content/nh8h0yt-m8tsv-fhy... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
GB
FR