URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: piedmontrescue.org
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-05-01 16:01:33 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-02 05:30:55 70.40.217.118box2129.bluehost.comNot listedAS46606 UNIFIEDLAYER-AS-1- USyes
2020-05-01 16:01:34 107.154.146.154107.154.146.154.ip.incapdns.netNot listedAS19551 INCAPSULA- USno
2020-05-01 16:01:34 45.60.96.154Not listedAS19551 INCAPSULA- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-05-01 16:01:34https://piedmontrescue.org/sport/rockstar.phpOfflineexe IcedID ext Trickbot ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-05-02 01:08:212c136e18f8c78317d6deea70a6be5e5922543dfdbcc924b8cc19019b8802fc40exe IcedID
2020-05-02 00:52:423655fd141632949c32d6f76901bd5a70e6c93576f086d1eb001924c9f22429b6exeTrickBot
2020-05-02 00:30:4163556a93a92d73d03429825cc10be2799c0355ba86295ae2ee206badcd43f011exe IcedID
2020-05-02 00:09:1608c4f3031606defc71d66d43bace6fa26496949a180090bec2958af37da2e35aexe IcedID
2020-05-01 23:51:21adb6e5f87a38764b3d0e075ae23ec167c9a2f121bc4a8b07ff396bddd1717d73exe TrickBot
2020-05-01 23:34:14530e17eecefa67b0ce7b12ca0ef97eb00b79410ff56c300c9770c34f21d5c276exe IcedID
2020-05-01 23:23:133e90a82ee57850a3e11c1e97978f91e78e9ef415b6a0bc1b65ac71739c6a4327exe TrickBot
2020-05-01 22:52:4159348372bcaa28cb42f341f7bec49472f93ac8ad254b5793ee6f8931157b4b5bexe TrickBot
2020-05-01 22:34:15c4f522e5e93bf9227f264cce8b45cf04b686202963f5db0cd3919da7fb1bc92aexe TrickBot
2020-05-01 22:17:1444d327e0955d3ff9c463cd98c59a39b104865be7ca7eca039535ee4bbafe5a08exe TrickBot
2020-05-01 21:29:40f112e4a3045461c398c16bfe54ed23a563c8a45212223f439345b41e1b62e91fexe IcedID
2020-05-01 20:38:2527a10558bb5cf4071fd39d82ad7ad166bc9f59a1ab67b8256e12e2f468affbe4exe TrickBot
2020-05-01 20:13:251b4c4c09088817aa547d2cc19a9fd13bcb60f0ecfd6fc900cb8eaff72d93cf74exe IcedID
2020-05-01 19:23:4798efcccc489463a79ba028185928a8ea2232314b45ddcaf54c25c8d309e97aa7exe IcedID
2020-05-01 19:23:15f7dc521812cfed243436753b915ec8ec11abd3a74d9a1d8663271bfd6fd47c07exe IcedID
2020-05-01 19:04:130b877d8ab64823914c59e993eefbe69c8e4c03d088751b3ae09b70e132ca7badexe IcedID
2020-05-01 18:45:15be78276b5f719dd5f30218338f7a04a7b409a69b701c24225c55e0dc78864cd5exe IcedID
2020-05-01 18:26:397aedd5f41423d53cfe4966e71a28b878e88a66939aea7cabf8a1a92c2e42f519exe IcedID
2020-05-01 17:56:15091bcbee6b66b6b13964a3fa117def8dd6075e6d6d1b86e31d4b36c124ef909dexe IcedID
2020-05-01 17:43:129855e6cab6dc7b89aa792aafd85bf39ac186954964427fc6e4c236a0a613d8e4exeIcedID
2020-05-01 16:02:10473970e2839af313ad61b9fc03d2dbd19e93e7b29ed81309c536248ed84e0eacexe TrickBot