URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | rankimprove.com |
|---|---|
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Not blocked |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Not blocked |
| OpenBLD : | Not blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2020-10-28 09:37:03 UTC |
| Total malware sites : | 2 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 2 (100%) |
| A record(s) observed : | 8 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 15:29:36 | 13.248.169.48 | a904c694c05102f30.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-04-27 15:29:36 | 76.223.54.146 | a904c694c05102f30.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-09-01 09:44:17 | 44.232.173.249 | ec2-44-232-173-249.us-west-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-09-01 09:44:17 | 52.40.42.113 | ec2-52-40-42-113.us-west-2.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2021-01-15 10:39:49 | 104.21.74.209 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2020-10-28 09:38:03 | 172.67.162.231 | Not listed | AS13335 CLOUDFLARENET | n/a | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-10-28 17:44:03 | http://rankimprove.com/may/lm/DHFF7QNxHR/ | Offline | doc emotet | |
| 2020-10-28 09:38:03 | https://rankimprove.com/may/lm/DHFF7QNxHR/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-10-28 11:00:56 | e2861831be4344cd8c0fe40b847eed9c317fd5d1349d8aef2da8580c95219ff7 | doc | Heodo | |
| 2020-10-28 10:32:11 | 60fb38864fb17fd842a14ca1e9a907c131ed2ece9c141251c7daa0676a22ef10 | doc | Heodo | |
| 2020-10-28 10:24:17 | 4ab9614151e8732d4f54a8dd18a8a329471ef031db0cac98b47c11f53d7c3a22 | doc | Heodo | |
| 2020-10-28 09:55:22 | f440f9758dd61ac185752b024897daf3b1ae6ac97407cff1f71d36cc6bfffc3f | doc | Heodo | |
| 2020-10-28 09:38:03 | fdb3f7af3bbff306674cd838932808a0ba6ca51888d5e54992df5c41a091aa94 | doc | Heodo |
US