URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nomadadesign.com.mx
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-19 13:28:06 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 13:09:54 15.197.225.128aec037177372cc6cd.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-04-27 13:09:54 3.33.251.168aec037177372cc6cd.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2020-11-05 05:25:57 104.248.211.186dos2r1078.servwingu.mxNot listedAS14061 DIGITALOCEAN-ASN- USno
2020-10-19 13:28:10 68.183.167.43dos2r1083.servwingu.mxNot listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-19 13:28:10http://nomadadesign.com.mx/F0xAutoConfig/attach...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-19 20:31:52455f0d38ef7a2fa26af12a20467fff0fd2c26e1b0b0269c1824a263fb6f1b6dadoc Heodo
2020-10-19 19:56:309363f5e5b8327d3d48fc6ec86fbe5628463d725ee19b8155cbd6ee410dc11cf8doc Heodo
2020-10-19 19:21:3541ac7d493b1557148e1fe3b89240f7e6819cd8bf0a4ed8bfbc789daa23a8359edocHeodo
2020-10-19 18:50:56314260b047fafb8a9e73e12c2d63b8fe7aca80e25fa1511e2c96a2bb40e26df4docHeodo
2020-10-19 18:15:21afacbe2b36a27b864ffaf4cc60eae312d6a7080c4a0822e29f8fb23b5019636edoc Heodo
2020-10-19 17:42:3801fef30b1519a4eaa558839ae9d4905b10f002571d44f140afb7fe2850c6fc20docHeodo
2020-10-19 17:30:445d349dc97b131734a22ef88c9825497239e6211786be5b294d6e7f9b7a41bc9ddocHeodo
2020-10-19 17:04:373837c3b95db5756f21d9920809ccbad0909eac42344076a4c12582f61acfcd6ddocHeodo
2020-10-19 16:41:1834ee8ba7a8157031f68b98e8ac7ad44be2eed233ac106ae095ea47884b6f8cf2docHeodo
2020-10-19 16:12:22a05e5c6098ba14cba82976f163c619e06db72ff518169f6f799e8c89f1fd0c7ddocHeodo
2020-10-19 15:42:576308486de691c912fecd3c2d8189b88f281ee4cea8a1fb122909541cc6b217cbdocHeodo
2020-10-19 15:27:385ecc6d05457c8d3f382c04c9186f74ec16a9d9da9c1d7c3dd0c392afae7cf852docHeodo
2020-10-19 14:56:3236ed59c1ee6e3358a027009660417aa0eab4de1d24ee4e17c0a0ae8b375aa325docHeodo
2020-10-19 14:27:531e8b04f61e8d6fc7b1bd0498cb69d0063ddb35817228b35297ec0e4174b144e6docHeodo
2020-10-19 14:10:2326c2e61794f91c5303493c18f5d4f311b5f1356a2ab1973f003333f53c52376adocHeodo
2020-10-19 14:00:39257a1d4cce20eec8aa07482d315d73b6569a490bd24b90a71021e7f4f4b940dbdocHeodo
2020-10-19 13:28:10946d379003a8578e7f97313a542c8bdaaabb216968b6cd6db6336ddcf7324d15docHeodo