URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: niebuur.nl
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-14 16:27:33 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 14:08:49 185.104.29.146web0155.zxcs.nlNot listedAS206281 AS-ZXCS- NLyes
2020-08-14 16:27:34 185.94.230.204premium04.totaalholding.nlNot listedAS48635 CLDIN-NL- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-14 16:27:34http://niebuur.nl/blog/i1h-pn0-8740/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-15 04:37:19e13d662598bb11ada832746d3255ee48f3b304a7966714104726abf2db3f6915docHeodo
2020-08-15 04:05:39911f2bfa86abc00f8fc2ea9dfbe597349baff6522fff47de22aa0ae77f31ece9docHeodo
2020-08-15 03:35:503d3319da15a4774593968e93c815aabd17f3ccdd973793e8f372028cf510fbeadocHeodo
2020-08-15 03:02:03bfcccc993aac3e4b5e5bcd112c1b5da71db89239b7158110aa32cf57c90ec112docHeodo
2020-08-15 02:35:08850db6418cb343d6e48f82dd435d9aac4459c3fefb9e9fb9ea1e2455a455a367docHeodo
2020-08-15 01:03:02608640cc09523824170abe5439a993ab6057204ad82c3c3af46ac0ebcf7cf38ddocHeodo
2020-08-15 00:42:33903b4b0dbf79ba01b1c8a324c887cf2e6e7ddff21d2cb2091ab77cbc6c13b467docHeodo
2020-08-15 00:06:01c9692b48a5184a6d4e5b8407d85ead0a011bb4184612d379f44b93f750aafe1ddocHeodo
2020-08-14 22:30:24fb275585028589c232253e318f2e4a1b8944cc529eb29e830047eee4180a169ddocHeodo
2020-08-14 22:13:025ac2b940e6a9bb518d04bcaa38e706d0604dd1c60691ebf2730c04e82aa11524docHeodo
2020-08-14 21:46:32b86c240ff73da180f757c89c445ffcabe432f5274d37075086d28f00b41871d4docHeodo
2020-08-14 21:25:50284869d2f6bf8757c4361deba6f72989a57e8fc84c93be00e7d2e9be8b979d61docHeodo
2020-08-14 21:01:0295e040446bc7580c574cbade1439630a10c27643ba7987ac158b8177db45fa5ddocHeodo
2020-08-14 20:19:094e4e13b049124c6db74594ed0351792442e0a91a82abc72f06601c9598c241c1docHeodo
2020-08-14 19:28:5195cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6docHeodo
2020-08-14 19:05:144a01c8e6ec280343403441c5e17c55359032885ef2cfae8ad4fc165f3911bac3docHeodo
2020-08-14 18:30:196b5f7ad9df134c6a4892ee11c2b9d5942174a02fa5e8f5f1b6e4e6c40c3583f6docHeodo
2020-08-14 17:01:10c55efd0311de10fc006e138fc287f244e1b942418fca25593dcc9a1f8f5101acdocHeodo
2020-08-14 16:39:38fe6706ad1c92c8c1fbf1bfaf7cdf31f3f58f5a324da318d3b548674c99a770dcdocHeodo
2020-08-14 16:27:3462693837af831b541e0cd5818e023baee2f0989413d3dd125721114a5b71ff69docHeodo