URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: salwa-khit.webmyidea.com
Domain registrar:OnlineNIC -
Domain registration date:2018-04-12 16:52:24 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 14:53:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-04-17 21:34:26 208.91.197.13Not listedAS40034 CONFLUENCE-NETWORK-INC- VGno
2022-01-11 14:53:04 95.111.249.189ip-189-249-111-95.static.contabo.netNot listedAS51167 CONTABO- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 14:53:04http://salwa-khit.webmyidea.com/assets/rJZuJkVi...Offlineemotet ext epoch4 redir-doc xls waga_tw
2022-01-11 14:53:04http://salwa-khit.webmyidea.com/assets/rJZuJkVi...Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-11 23:12:26429e0de91bc404f5fc886f0618177f5bc49fe0da3940e98426c5d5cd8aed57cfxlsHeodo
2022-01-11 22:40:38f326b9b9af87bd43878455ac75b4e61fadd71bdfcebf5b4508525cbbb4e8038bxls Heodo
2022-01-11 22:10:11a3977aa3c358df0d9777be64e5c10b4a874fd0eac63183e92837d58038e5c4c1xls Heodo
2022-01-11 21:48:43e7065618e785e98792d570656fd412ecf695c45ec5a8123d04cf4ee302d225bfxlsSilentBuilder
2022-01-11 21:23:18dc1a568534305e8dd82443bd62f3fefe364de2073558c8237bbe099593714259xlsSilentBuilder
2022-01-11 21:04:531db259b0063d26f9af684e7246d336250e289514a4e900eab1337ee9981a866bxls Heodo
2022-01-11 20:49:55b5d8116e0b4f01eb2affa09d857d1be4df2e18dd793e4ab0b6ad28e0d5eadc15xlsHeodo
2022-01-11 20:21:52d92b0ebb1f64086c8c4d5b238f3683a3319bcf041cdfc9e6736f742a260a5ce2xlsSilentBuilder
2022-01-11 19:55:04426fda840765e44250686f1102e902242babe0cea36a756beac6c0757a73c28axls SilentBuilder
2022-01-11 19:32:42e8ada03261f05e1c91d784bf58d10322d3765c686bb4a52278362e0e62288d1bxls SilentBuilder
2022-01-11 19:07:20afe04f54612c86612a56bf8a3a228a2aeae275f4730552228f8a4bb6f71c292exlsSilentBuilder
2022-01-11 18:49:2318e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51xlsSilentBuilder
2022-01-11 18:26:5960fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440axls SilentBuilder
2022-01-11 18:02:35e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75xls SilentBuilder
2022-01-11 17:39:05b1facac75e8c07b20f413b7083f889cd502c32847a97c5cbed0d3e4051f9a139xlsSilentBuilder
2022-01-11 17:24:1554e67293d34aa1794e6227fa0641f88d5206b073319b30e5e68e238f8b698b98xls SilentBuilder
2022-01-11 17:04:1613a116b4d63f461fc1ef2413ad32b486cefd432df4324dd3f9fa6ca9697a65d3xls Heodo
2022-01-11 16:51:33b68760371e947df68d4f69a1f9b43a56de082932df771b0ef088adaae130931cxls SilentBuilder
2022-01-11 16:25:507955874a069fbde3eb5144ea8420f8b9e80d0c8ccd822c21b54150e53608116cxlsSilentBuilder
2022-01-11 16:18:002f80ecbe8f3eb45c354fb36640dc4be6b13064be8550f2d49e41090e5c113b72xlsHeodo
2022-01-11 15:55:280b52372793be51e4313df2cb64a2b43650e47eb55920506fa6ac3f0726da0a89xlsSilentBuilder
2022-01-11 15:43:289f968d781db29617f0b9954b931d6fd3cf4ad16b365ae3a64441eba7a84d611dhtml  
2022-01-11 15:22:39d77daa81350a4b38ba1ed4ad068297d5680f054a489a4b9004aaea0a9bdfc180html  
2022-01-11 15:19:38bdb3e9a556bc850867023c8e1c5ea1e20cda48c72bd0396ef667d3352b14d65fxlsSilentBuilder
2022-01-11 15:05:463dbfb9a583de71af6ce19cbfb294476ab7d6fcfd2fe42c9bf38886ace35c58fbxlsSilentBuilder
2022-01-11 14:53:0458f9d3255466b6011091023f84f65a0105f354ba16f12c384387c56b4980a7d4html  
2022-01-11 14:53:04125d84a3e35c42f4464704bc17b835fd488c8116476a7c61d170e47def200dd6xls Heodo