URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: noor.school
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-26 08:53:03 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-28 08:00:48 13.248.169.48a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-04-28 08:00:49 76.223.54.146a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-09-06 10:18:14 166.117.110.61Not listedAS16509 AMAZON-02- USno
2025-09-06 10:18:14 99.83.161.153a2b7bf3398455f345.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2021-04-17 17:19:29 185.181.180.123live.nooridc.irNot listedAS206596 NOOR-IDC- IRno
2020-10-26 08:53:05 185.181.181.35ns1.noor.landNot listedAS206596 NOOR-IDC- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-26 08:53:05https://noor.school/lmstemp/attachments/jafUIEo...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-26 14:37:56b66a18bc5690f1ee03097c641de0c0232d3b9f8d8868100d02110176efb474f1docHeodo
2020-10-26 14:29:37ff68589efb48ed334df874116da99513e4be8d9b93dd70073f912a46f1c7276bdocHeodo
2020-10-26 14:05:118147739aff1074f3aa45f6505332f254c1d2750f1f4cdf2047acc545a8656032docHeodo
2020-10-26 13:56:2550ae991ce6ef920b330eab06fed63e4189477c5b5c449311b9b3a509c174950adocHeodo
2020-10-26 13:37:019051c3262b2cf8fe3c7d6e53b49107c37a032d9a2e542c5f7ba91c45eaf7310edocHeodo
2020-10-26 13:10:38b09c1e57573cb81b0caf6e7689249181086b61251099164768fe6546c4caa9e6docHeodo
2020-10-26 11:06:57d6f7bdb1b5ff4287a1bb5679161b98f7941f0091197b37d04fba163501754706docHeodo
2020-10-26 10:51:17837394e50387f3b76947bdc15f7e1693415f857683b21038e0d70e6a976f45f4docHeodo
2020-10-26 10:44:597568f48fe0645ea9cdd165c0432da115295430c4e8064301c518360ad8153dbedocHeodo
2020-10-26 10:27:44001c7f2cf9518d78d50711633e4f0cb168bbc4ab2c923ead7c41febf6e3fdfaddocHeodo
2020-10-26 10:16:436c73d0f17a9c1e3d6139834005569d2622fcb6c0b85c46b91e924b0377e9d997docHeodo
2020-10-26 09:59:1265c041247137b7d9c65793ffa57b76456395fe67c3c05c88529df1782f93e13adocHeodo
2020-10-26 09:36:39eae4719f917beb5858ab2c6234b7207c53b3742b1d8e86db08cf5a74e860bc2ddocHeodo
2020-10-26 09:30:41c4a0319dff56c784d5a9d4f826f592f0aab4667de8e50dd45a9f6801a1175960docHeodo
2020-10-26 09:11:025a81cd26189c9f1364aba385c3519d1863c888a7361e722584d55f148aa6c4c4doc Heodo
2020-10-26 08:53:044a806be3622fde5e56f7d49e52fcfc48d458fbc78ca20a857a193d4c98124413doc Heodo