URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: newtop.one
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-20 21:17:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-17 20:12:11 34.41.139.193193.139.41.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USyes
2025-06-17 20:12:11 34.159.223.4343.223.159.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2025-04-27 12:38:21 34.132.102.66.102.132.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2025-04-27 12:38:21 34.136.111.8181.111.136.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-09-11 10:38:53 104.21.38.66Not listedAS13335 CLOUDFLARENETn/ano
2021-09-11 10:38:53 172.67.219.184Not listedAS13335 CLOUDFLARENETn/ano
2021-07-16 13:51:33 75.2.115.196a815a0b269b119624.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-02-24 14:54:15 209.99.40.222209-99-40-222.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno
2021-01-20 21:17:06 103.214.108.66cpanel10.ipxcore.comNot listedAS63018 DEDICATED- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-21 00:22:06http://newtop.one/responsives/z/Offlineemotet ext epoch1 exe heodo ext Cryptolaemus1
2021-01-20 21:17:06https://newtop.one/responsives/z/Offlineemotet ext epoch1 exe heodo ext waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-21 00:22:0606040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafdllHeodo
2021-01-20 21:34:5706040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafdllHeodo
2021-01-20 21:26:22016a09389a4b5d9b311f78215343e9cd30a689e6543d6c3cff3e8a83f7dc520ddll Heodo
2021-01-20 21:17:0613e5f641e84c94fc8cd09f51514765c5b4bf83d1bda8b4f9f9b737561880834adll Heodo