URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: s3.us-east-1.amazonaws.com
Domain registrar:MarkMonitor -
Domain registration date:2005-08-18 02:10:45 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-11-29 06:57:03 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :8'718

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-29 15:50:00 54.231.171.224s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2023-12-10 15:23:49 52.217.108.46s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2023-12-16 10:08:17 54.231.196.48s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2025-05-20 12:44:44 16.15.185.110Not listedAS14618 AMAZON-AES- USyes
2025-09-22 20:02:05 16.15.187.144Not listedAS14618 AMAZON-AES- USyes
2023-11-30 04:00:36 52.216.51.112s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-11-30 17:13:37 54.231.136.16s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-12-01 01:11:22 52.216.37.24s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-12-03 06:03:01 54.231.235.72s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2023-12-05 17:24:56 54.231.169.168s3-1.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-29 06:58:00https://s3.us-east-1.amazonaws.com/010ad332/Emb...OfflineCoinMiner GuLoader ext Anonymous
2023-11-29 06:57:23https://s3.us-east-1.amazonaws.com/010ad332/Goo...OfflineCoinMiner GuLoader ext Anonymous
2023-11-29 06:57:14https://s3.us-east-1.amazonaws.com/010ad332/Bra...OfflineCoinMiner GuLoader ext Anonymous
2023-11-29 06:57:13https://s3.us-east-1.amazonaws.com/010ad332/Goo...OfflineCoinMiner GuLoader ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-11-29 06:57:58ee4f4c4d03033e6a3361948b56f83dda91d82f4433a4c744c1b7124e73dab56eexeGuLoader
2023-11-29 06:57:222d7347d8a4191e61b13372d61fb5fb884a68ebea6469547edb2915d89f976ae1exeGuLoader
2023-11-29 06:57:1225368f648491ac3483fd20c5cbef764cb920e0cab6fa287bb57cda03d70681d5exeGuLoader
2023-11-29 06:57:102fa34c4fc0ec5810af33c51465647aa5f90654273f3e0756325c8d4817b17a64exeCoinMiner