URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2022-04-24 23:43:20 | 209.99.40.222 | 209-99-40-222.fwd.datafoundry.com | Not listed | AS23005 SWITCH-LTD | US | no |
| 2022-01-19 17:21:03 | 31.47.76.124 | waf.neodigit.net | Not listed | AS15954 Tecnocratica | ES | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-01-19 17:21:03 | http://ocyan.pro/b/WcJHuDuyet/ | Offline | emotet | |
| 2022-01-19 17:21:03 | http://ocyan.pro/b/WcJHuDuyet/?i=1 | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-01-19 17:25:14 | b0610f43f2e9d1f158eb4dec68ce85c03890d71a428176472644163dcbf79bd6 | xls | Heodo | |
| 2022-01-19 17:21:03 | d21a966ec86d5951b47eed30680a0bc26db5eec8bfe92a9de029b63562c8123e | html | ||
| 2022-01-19 17:21:03 | aae035c074dd1a0f16ab7381887f6a9f8929c6b8f82d78d8b976bfa14151f8a9 | xls | Heodo |

US
ES