URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nlsms.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-14 16:08:03 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-05 07:17:43 159.203.129.1441471213.cloudwaysapps.comNot listedAS14061 DIGITALOCEAN-ASN- USyes
2025-05-29 20:48:04 15.197.148.33a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-05-29 20:48:04 3.33.130.190a2aa9ff50de748dbe.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2025-04-28 10:45:12 104.21.44.81Not listedAS13335 CLOUDFLARENETn/ano
2025-04-28 10:45:12 172.67.197.149Not listedAS13335 CLOUDFLARENETn/ano
2020-08-31 18:43:40 104.26.14.34Not listedAS13335 CLOUDFLARENETn/ano
2020-08-31 18:43:40 104.26.15.34Not listedAS13335 CLOUDFLARENETn/ano
2020-08-31 18:43:40 172.67.70.15Not listedAS13335 CLOUDFLARENETn/ano
2020-08-14 16:08:04 35.171.128.33ec2-35-171-128-33.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-14 16:08:04http://nlsms.com/3zdkjWTLd0/Overview/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-15 10:28:5955f8854dbcaa2832aa10f768c129ab27544b5b153c7e4ea008f7ae9444681eecdocHeodo
2020-08-15 10:00:29e3dc10847c610fb756b701eb6c9eff581d98adda60bbd1df9ca1c41f43e6710fdocHeodo
2020-08-15 09:30:15a570a76cfdaf487a4b7306a5c2212e3f7ea7f2ef673e1f9819090cf6e84abe5bdocHeodo
2020-08-15 09:12:56f8b496c0f286d5a7fccc4ede8b957465c515601307821f28b9353d38e79ad46edocHeodo
2020-08-15 08:53:1759931fc10797afb244cd5fad842662e6195c228946e63c010c8d619147c57a21docHeodo
2020-08-15 08:31:08e4755fb87595acbe2efa782aba44cec85fc8e2fc968d3e54d60b9459ed8b4c9cdocHeodo
2020-08-15 07:44:21ee97f9a6d45b17138a70dd059c12b950dc5cfd7ea2ea195a0174e656506608c9docHeodo
2020-08-15 06:50:40efaf2ad634e680575e71775d7e7081272a70e9d96a70a2da8691a0e4e95f21aedocHeodo
2020-08-15 06:18:13bcac38ffbb51d86e6aee3890c75a867b75b2e54ee530fa7fc6a23be61e53a0a7docHeodo
2020-08-15 05:55:2015f3fb6dfa920996f70baeb95d6a459700a4d0822b25ec3ea7a37ea056b76977docHeodo
2020-08-15 05:36:5439305c6dbc4d4612cfc18efe4df05ca5898cd752b92635429f393159a7734448docHeodo
2020-08-15 05:05:36df46f526192787058b497745baa89076f7a146abf7904a166ff3c88913d6fe8ddocHeodo
2020-08-15 04:47:374277af4aea547eeb89b49825bfa0ae17686669afea0350b9850d3ad6ce0928b6docHeodo
2020-08-15 04:37:310d12b5e9f5f5999ef15565f91ef3a2e631ca0a35c8747a808a542b2a8d8100b2docHeodo
2020-08-15 04:05:445cf289830a79e1608f952fbb47868d1791f30a61fca435f7f76c5bd33b623451docHeodo
2020-08-15 03:35:580a9e7d8e4b00631d24afb44e7e5f6ad531d8024410570195352e9b4666d7141ddocHeodo
2020-08-15 03:01:512fabcc2eb662a103f6fb0067a2d8f0b522149acda448296223c7fe79bdc2e2eadocHeodo
2020-08-15 02:35:082052c0368adb81017535da7aa5dae9846fb5cdd1ad7b3dc089d9c2b7152608bbdocHeodo
2020-08-15 01:03:022b1defff772c7e6448125be396c10f7b34b8bbe01d902999824e216358a78338docHeodo
2020-08-15 00:42:07c1f1f9b4ea3631f3eaf9afa4e8f27d8dcfbcbce4c65a47b6ca4778a833104ec1docHeodo
2020-08-15 00:05:512282676dff6e201e68e1817f507dbb2f5ecbeb498367e7aada3916d32e89511ddocHeodo
2020-08-14 22:30:5237452de46a62ad1ddf71058e28b5d4eb72229bb3db88c988b9460318f5b3fce4docHeodo
2020-08-14 22:13:06c837fd8744bd36a0ac0a3a3f11e102063d60651777ee888c2f3f8e83c54a6483docHeodo
2020-08-14 21:58:0980d4aebc98c2d2c77e1a9e3a6c7efc391f37e1f7386d7943bffa74d5d5a29eaedocHeodo
2020-08-14 21:37:22e8444ce3ccd2f148db30a39cc0b699662f8cf96302119a5e7f2dd0ce42a94cdbdocHeodo
2020-08-14 21:22:17025ef755f910aeb461ef36e7993d5201b78cb2aded971137274727ec619d72a1docHeodo
2020-08-14 20:57:37739eab0c4f294e4ba8fff9f685d6ab8303b5e4ab1caf9482d846afec5aeab316docHeodo
2020-08-14 20:30:254a4029474014846a17463695f4af7917f8fc4fd250f36e96bcc1964d4bce93d0docHeodo
2020-08-14 19:54:4796b6cab1427a652a35407967a7c4f7e6bb2bd63159d8e2510793ea9b9e76093bdocHeodo
2020-08-14 19:28:39f622719824dddb15ad882647aa93a4c1ada60438b2848007a681d5dede734120docHeodo
2020-08-14 19:05:5370feb9efa08111fe7c484ceb84655548d7cb35980e388a8832207a68bc29fc58docHeodo
2020-08-14 18:30:281d789fb3f153fbe558cd34bc28f0bc8fc0471c554cc60745df920166bc0d98efdocHeodo
2020-08-14 17:00:079ae4963720b53512f3c5db907f8e269667c54d3ad4fd0dbf742346936449c84edocHeodo
2020-08-14 16:39:22b5ced3fd9b5203a48e44f9df4cb09216c9527f2bdae51b0d7ee1a53e51c12350docHeodo
2020-08-14 16:08:045ffcf219f1a25b46f3bd96ea008d712ae48a9a6e15f59e52656330cfd54c94cfdocHeodo