URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-04 19:57:52 | 104.21.15.45 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-11-04 19:57:52 | 172.67.205.134 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-08-20 19:45:44 | 13.248.213.45 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-08-20 19:45:44 | 76.223.67.189 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 07:52:59 | 15.197.148.33 | a2aa9ff50de748dbe.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 07:52:59 | 3.33.130.190 | a2aa9ff50de748dbe.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2022-11-23 04:03:02 | 72.167.57.119 | 119.57.167.72.host.secureserver.net | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | US | no |
| 2022-01-11 18:57:05 | 64.13.192.174 | acmkokeaas.gs01.gridserver.com | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-01-11 18:57:05 | http://omarcardenas.com/b/288051704982/ | Offline | emotet | |
| 2022-01-11 18:57:05 | http://omarcardenas.com/b/288051704982/?i=1 | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-11-23 07:46:17 | e55ce4bc7ca054665ac48b9640d2f0f3bc4a83af6c95b4019b28c4d49ba669b9 | xlsm | Heodo | |
| 2022-01-11 19:33:34 | 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2 | xlsm | Heodo | |
| 2022-01-11 19:20:53 | 5fc032fa83b6354788c50be24a92d24773e71b9dc7cb7522f650afc2c8749d48 | xlsm | Heodo | |
| 2022-01-11 18:57:04 | b7c8f116535fcd9532cae598b87c18ed9657c6e172dc2bd5744776f7e8d84bd9 | html | ||
| 2022-01-11 18:57:04 | 8225d340f62e0a9d2fd91acc14510e7df52c5649f1edfe0ba62e00f859d597cc | xlsm | Heodo |

US