URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: reumatismclinic.com
Domain registrar:GoDaddy -
Domain registration date:2021-02-01 08:56:02 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-03 16:31:03 UTC
Total malware sites :1
A record(s) observed :16

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-04-28 09:48:24 34.197.121.219ec2-34-197-121-219.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-28 09:48:18 34.228.163.56ec2-34-228-163-56.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-05-01 04:45:33 52.0.116.71ec2-52-0-116-71.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-05-01 04:45:33 52.86.107.36ec2-52-86-107-36.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-04-23 20:34:21 34.202.173.75ec2-34-202-173-75.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-23 10:16:02 54.152.168.219ec2-54-152-168-219.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-23 10:16:02 52.45.28.232ec2-52-45-28-232.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-23 20:34:21 52.73.209.231ec2-52-73-209-231.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-23 10:16:02 107.23.135.136ec2-107-23-135-136.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2023-04-23 10:16:02 3.225.246.245ec2-3-225-246-245.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-03 16:31:12http://reumatismclinic.com/-/scCnm3mbJRpsaBKBbrC/Offlinedll emotet ext epoch5 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-04 18:42:40155b8841386ef7225ddabc01e216554117c59323d54ef4b27ff406c736fa50dfdllHeodo
2022-02-04 17:14:49f3bc43666a299b370d7cd285abe0c1a58b123060d9c73e15376fed03a7de79c4dll Heodo
2022-02-04 16:50:32c63ddb95a19c24b0551585d85e90f8ce580276b419cd91fa325704b7f734a3acdll Heodo
2022-02-04 16:44:0298715d30661eee6d612071bc1a77f8d993e49dd9af2b390f2b35e8479261e332dll Heodo
2022-02-04 15:53:32162826ef4f1444951856306199df336c4c0562b5cc5d88c15fca4d504075517adll Heodo
2022-02-04 14:00:505f460aad6f1839039168e220162217820d7eb4a6cb9c18fa5246327655d7ddb7dll Heodo
2022-02-04 13:18:309b996419cb6ddc9019ba21541cadb8b10400f51968a73f86b67b99854a7b9c39dll Heodo
2022-02-04 12:47:240bca6758c92ae9807d9edc25e27857f80655470bb88d2a30998a970fe4f31c6bdll Heodo
2022-02-04 11:30:254556c8cadadc1ed75fd4ac92363dfd31389026d2e992c0c8047d968f03673623dll Heodo
2022-02-04 10:31:32892a67c71536447d37b6e1876b418bc417c026896b315d547399f1f9db829acbdll Heodo
2022-02-04 10:09:17b6380ad214086c7f1446ff6ec18cca44b162c03ab89445282cb3e58701c06878dll Heodo
2022-02-04 08:33:537928212e14bfdc583655106b571aed5cd0c4931857a1eb5d3bb97d112317b16adll Heodo
2022-02-04 08:19:30c91ab95e1618685f49936c43829f01657e1a8c33f972b786355223d2a18c72d6dll Heodo
2022-02-04 07:21:214758e3a8400ec9afaf334d022ca0b26b7de73f2958059c13f49578d2741cad6ddll Heodo
2022-02-04 05:01:44d2a1343070e14af6f083a7a0ee785652a0cbad76175ad97241b23b1eb1a06df0dll Heodo
2022-02-04 03:57:45c2d21fd6a25bd2068f38d8002596fb041bda3eff5e2f21836a8b7d1f3bfb8481dll Heodo
2022-02-04 02:45:39a10dc0086924c5996dacfe7cc3f1fc6eaa992050c243e04e916b1ce30e44a5a9dll Heodo
2022-02-04 01:45:18d726a786ea19c09fc8284326c3b810ce2750216b000f79cac32f23854b417534dll Heodo
2022-02-04 01:30:13721d04bbddbd3912e6e0373f5ef53772d1af67a2a559c7acc75e2de9812b7cd0dll Heodo
2022-02-04 00:41:3919788d770012f806cc239d7a47440e27ed48dba30f8e9f4d82fcf5dc84375fdcdll Heodo
2022-02-04 00:20:075ce87e1290b19f74bf39ebd5977df7d3c06e7868eab797b1a86f8d3deba51b2edllHeodo
2022-02-03 22:38:380f44deb5c4ffc17768ca0a64232536179737fd199c7218ffd869ef65731d1466dll Heodo
2022-02-03 22:32:109b4d7a2b3a9f813955bc3b9554172c59718403e89f35a095e572644d5b02f4acdll Heodo
2022-02-03 22:07:5927eff1acc3aace958c1702844b639b0e57de5f6cdaf791147b7e6d80477a2eeadll Heodo
2022-02-03 20:44:2053e70a248f9aa47731a47f7dddd7d762161b78af140380b95c0759fa9e7e5095dll Heodo
2022-02-03 19:43:118e9667d47ed501d1def068cf50c8f9af531049133f664bb6da76a93e103bb17ddll Heodo
2022-02-03 19:18:3645608c2e465ce3ae7c65b4afd5edd86d80ade8f21b892561a34cf6a588c844dadllHeodo
2022-02-03 18:21:0198fc5af29898721548ad07b735367c946fae9ae2ffb60c98ec7df5ca16841ecadll Heodo
2022-02-03 16:57:55970c3fe800bec11d5a83790d1a4f9ebbf3185656ad207644cc3ad5cac7f420a1dll Heodo
2022-02-03 16:31:12230cecf6fedaa991617a2c86117ab42365a063b9d5eeeff1f021f9699cb1cdaedll Heodo