URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: quicktowtowing.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-20 20:03:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-27 21:29:42 199.16.172.171Not listedAS2635 AUTOMATTIC- USyes
2025-06-27 21:29:42 199.16.173.148Not listedAS2635 AUTOMATTIC- USyes
2025-04-27 13:08:53 141.193.213.10Not listedAS209242 CLOUDFLARESPECTRUM- USno
2025-04-27 13:08:53 141.193.213.11Not listedAS209242 CLOUDFLARESPECTRUM- USno
2020-10-20 20:04:06 206.189.212.65Not listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-27 13:40:06https://quicktowtowing.com/wp-content/mu-plugin...Offlineemotet ext epoch1 exe heodo ext Cryptolaemus1
2020-10-20 20:04:06https://quicktowtowing.com/indexing/N2/Offlineemotet ext epoch1 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-29 13:39:323c14e86debedf5a247374cd4baf5628f3d577478a10020f14c42d4721f9742a5exeHeodo
2020-10-29 13:08:127e0c71f53590e6286340bb5f7ede2e19d5efe74fb76294c5057595c3dfcf2a93exe Heodo
2020-10-29 12:49:316ea9b9c2189d74da5a9fc28efe82956f2fed98420c4734259b1ce8a5a358b420exeHeodo
2020-10-29 12:06:16ad27c8e950196e9426b4dbed17b5c63dd8287f496fd53225d25f96b65c77d343exeHeodo
2020-10-29 11:57:349487b55ad32d8351489387583bf9b2f8ff761dc5ca36c13613283543cd07c0b7exe Heodo
2020-10-29 11:30:448c4047fbbabb58880337dda69679d60b05db17c4d2e5495218b7b3b5e000797aexeHeodo
2020-10-27 15:52:03c1b93ced1b6f70e7bcd4ddbf20d7e2e68890afe75e1b6190d9740851b9168083exeHeodo
2020-10-27 15:43:47d72013673e30549cdf842924e7cd4bbc369ca9e643ce1443449fb55cef4722aaexe Heodo
2020-10-27 15:23:207cb397028c091a0473a8e2733c728587572c48ced41875b152d30136ca09f6f4exe Heodo
2020-10-27 14:56:16bb0c62ca0db0b0b3d67b7662098dae92d7703176d0c7258a512b0c11c2c00949exe Heodo
2020-10-27 14:39:03b374ffbb05b17c7cb0744c577e20050564b9079f7af1b0c49e7ff814a71ee7aaexe Heodo
2020-10-27 14:21:15d333ff8ff182a29158a384f77227a682a5cd02002ce4b2ecb9ba0af9b5400a80exe Heodo
2020-10-27 14:10:189e8471b96d9cd309383e511873b368ea4935f8fa6f88c452a98da2f76b646817exe Heodo
2020-10-27 13:53:23f885716d560c3f67862e84130e6fdce81bef0468c638a95d23fe6aec4d258844exe Heodo
2020-10-27 13:40:0654ca61558b79ec0f971d097498190cc6ee2dcb15fab400e1f43a658144102ab6exe Heodo
2020-10-20 21:37:10ce2e4a5ad22c37a7e90e70a173c6820b4285697f92f041cdd7980d72d18e4901exe Heodo
2020-10-20 21:14:372df7bb2a14dd955259a91cbda9d69e5e784544815c8004bf9490854fffdcb8bdexe Heodo
2020-10-20 20:34:495836803ae8cd96eb1b4fcf871a7aea44c4af4e87464a45f2716eeb060a8d01dcexeHeodo
2020-10-20 20:23:20886f2dfc71db67ab320ff5e7f720d3ecc8576e440a965dd05ac2b30af67ff8beexeHeodo
2020-10-20 20:04:06f1d08ac2b403fba5e128224c9be879e967ff80249addc29ea6b41cbf521b4be0exeHeodo