URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nairapath.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-13 19:35:03 UTC
Total malware sites :1
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-24 22:47:49 13.223.25.84ec2-13-223-25-84.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes
2025-08-24 22:47:50 54.243.117.197ec2-54-243-117-197.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USyes
2025-08-26 15:12:49 52.201.53.166ec2-52-201-53-166.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2025-08-26 15:12:49 98.82.42.139ec2-98-82-42-139.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2025-06-06 14:58:37 199.59.243.228Not listedAS16509 AMAZON-02- USno
2025-04-27 15:19:37 66.29.132.127business141-4.web-hosting.comNot listedAS22612 NAMECHEAP-NET- USno
2020-08-20 19:41:48 199.188.201.77server275-2.web-hosting.comNot listedAS22612 NAMECHEAP-NET- USno
2020-08-13 19:35:04 51.89.20.92ns3143972.ip-51-89-20.euNot listedAS16276 OVH- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-13 19:35:04http://nairapath.com/wp-includes/XmYO/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-14 05:37:22865aa27f909822b77734136c2ce238a258cbf8a6041b588f5fb75c284fab5d26docHeodo
2020-08-14 05:21:04c32ebf07a4f2324cc33cf6e7c975c375621c519fa654fc27303c9a812293fd7fdocHeodo
2020-08-14 05:04:18854fcd9b34f74cfd7956a1bfd5de137afaa0c79aa3e1e80ccc4f87410e0e6159docHeodo
2020-08-14 04:35:193d8831fa48eda1b1975a84cde54f8775ceecc95fa6ae4278a9ee533cf37d9d8fdocHeodo
2020-08-14 04:13:198b725e5a090dcb30815c5df978e72af9a04372b9fda6729678004e9bdd617ce6docHeodo
2020-08-14 02:42:49167459762dfa748a07ae8e4d2479e9733ad4d66e0d833453daa2038e833efa29docHeodo
2020-08-14 02:27:205b5e18fb115c6b3ac31082a0b3d864e051d30cac7f5a27ce29d97c3deed87a5edocHeodo
2020-08-14 00:50:570b134d91d537beab9f4e700b126eb1b43b69c80126818592cef4697fce08263bdocHeodo
2020-08-14 00:34:414398bc31070f761b318b30f297d363b006ed9e84c6af0aa45ad140f57e7c1529docHeodo
2020-08-14 00:15:27532d6be9513e3dea9cfb7040d4e2b0878429f90b84e8c3229ba775ff99dcfbbcdocHeodo
2020-08-13 23:49:501ffe441dc57cc6d6fab94949536fc37e1ee200c8108f3345a48a04ca268d097edocHeodo
2020-08-13 22:21:035631e8cae72c63a40c3b2b7558736633f75b424eff6bad19103ca6d559955528docHeodo
2020-08-13 22:01:4088d310c1de24f5a780b5269aeff8f47a6715c4fcc531df6ad2e8b2fce834773bdocHeodo
2020-08-13 21:38:55ff68f4adbb2d5f421b94ec8c2ca343c8dc807544237928a2617bb4c1dd32b7b8docHeodo
2020-08-13 21:22:36653065e50db8318e4c980f45418849681df513e216b29c07cc7036442b0f9cfedocHeodo
2020-08-13 21:00:5749d66f1859784a289e46f5690a521c15cb397cb29ad8db6882806c03628a4b97docHeodo
2020-08-13 19:35:045068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642edocHeodo