URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-28 00:57:46 | 93.191.158.80 | linux214.dandomain.dk | Not listed | AS48854 team-blue-denmark | DK | yes |
| 2022-05-30 17:10:24 | 178.62.237.71 | Not listed | AS14061 DIGITALOCEAN-ASN | NL | no | |
| 2022-03-18 10:40:10 | 161.35.223.214 | 971517.cloudwaysapps.com | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-03-18 10:40:10 | https://s4tiva.com/wp-content/pO/ | Offline | dll emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-03-18 12:57:10 | c11990c4bfc1fe9586263eaeeabd5b194e43b30459609dd6ddd7aa229ebf0018 | dll | Heodo | |
| 2022-03-18 12:51:52 | 7ab1aea91407630b2810fbbffdbd7e4a4fe73eb6903d8ccbe563e9b39132b405 | dll | Heodo | |
| 2022-03-18 11:53:18 | 0ebeb9fd250d1929da9327d7f6bd9ce74e3e2a6fd26fb82d5e1912cc810299d5 | dll | Heodo | |
| 2022-03-18 11:36:17 | 72f73093f4259427f0ae57370a8cad172db4c8f44b85c97fca1d2a5d8e8d4ea9 | dll | Heodo | |
| 2022-03-18 11:12:28 | f7092d572ffc4bdf8e61ce9e10b22268aaf0732b40a9dbf27324e89b56a1afc3 | dll | Heodo | |
| 2022-03-18 10:40:09 | c1ec107518cc570811a6cc25591f47ffa769538853231d8ee63a692df4cea945 | dll | Heodo |

DK
NL