URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-10-11 05:55:37 | 178.63.165.81 | static.81.165.63.178.clients.your-server.de | Not listed | AS24940 HETZNER-AS | DE | yes |
| 2025-04-30 07:07:58 | 95.217.119.130 | javid.shetabanhost.com | Not listed | AS24940 HETZNER-AS | FI | no |
| 2021-01-22 04:34:04 | 185.18.215.78 | Not listed | AS48715 SEFROYEKPARDAZENG-AS | IR | no | |
| 2021-09-25 11:26:49 | 185.143.233.120 | Not listed | AS205585 ARVANCLOUD-CDN-IR | IR | no | |
| 2021-09-25 11:26:49 | 185.143.234.120 | Not listed | AS205585 ARVANCLOUD-CDN-IR | IR | no | |
| 2021-09-05 01:03:02 | 104.21.15.12 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2021-09-05 01:03:02 | 172.67.160.254 | Not listed | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-01-22 04:34:04 | http://nafis24.com/wp-content/zJ3QQDV84IXAhPVyP... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-01-22 16:30:03 | 9ba0039bc176e474fdeeb96eaf3feac9ad506e1a1098355a5b07c34d54ca789a | doc | Heodo | |
| 2021-01-22 16:06:56 | 64984623624fbec06c253d1396140873193f53152579eb4f8c57117665a3ca03 | doc | Heodo | |
| 2021-01-22 15:53:10 | f82f36ec2c4010892c1dbd0e9c4c1315653eb04b2cc3905bdc90215adfe50777 | doc | Heodo | |
| 2021-01-22 15:40:43 | 80ba08b994580df8c476bec4479e8fc942b9da8ea70810fce0658e56af6ca5f8 | doc | Heodo | |
| 2021-01-22 15:25:48 | 9e2c5e3ffc4db3771082aa0ed3a6c30821f0545c540f6541d087d1e65e733cde | doc | Heodo | |
| 2021-01-22 15:15:49 | 46ecb2bd799ed8838178b39b07df00329f9348fd48545a9e6be9b76e5ea6de09 | doc | Heodo | |
| 2021-01-22 04:34:04 | 3a0235b5137c1d8dffa67e97c6dbe13cfc7117e3c62dfee05d8897acdea83b5c | doc | Heodo |
DE
FI
IR