URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: scootair.co.il
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-14 13:12:03 UTC
Total malware sites :1
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 22:36:36 88.218.117.30s-vps-il-619.upress.ioNot listedAS209622 upress-drb- ILyes
2021-01-14 00:39:45 104.21.10.53Not listedAS13335 CLOUDFLARENETn/ano
2020-12-29 21:44:05 172.67.131.61Not listedAS13335 CLOUDFLARENETn/ano
2020-12-29 21:44:05 104.28.10.52Not listedAS13335 CLOUDFLARENET- GBno
2020-12-29 21:44:04 104.28.11.52Not listedAS13335 CLOUDFLARENET- JEno
2020-10-14 15:45:07 209.182.238.215Not listedAS29802 HVC-AS- DEno
2020-09-14 13:12:05 185.106.128.132coca.co.ilNot listedAS44709 CLOUDWEBMANAGE-IL- ILno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-14 13:12:05https://scootair.co.il/agm/http://sites/pxempVa...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-14 19:14:398014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15docHeodo
2020-09-14 18:54:585171e0e602e27c4122239e9c7833c603beebb69bea148c5d29341990af469f55docHeodo
2020-09-14 18:40:599071af554116b7e5e92cbd63922f2d577d1fd912ed4fd121ab0762aa8b2dd589docHeodo
2020-09-14 18:16:18707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340docHeodo
2020-09-14 18:07:383172b64121f2b22437fb59afa7124acec2dde11e932b900ab8b1e038be9f8f08docHeodo
2020-09-14 17:38:2641a5219800a60a147e301cb5ee472f45de2130aa095d82a52fa81121b5881860docHeodo
2020-09-14 17:20:44f463cf4d92f75e61f9c1a076fe61975011301f50d20a575e76b350fdaabf40c7docHeodo
2020-09-14 17:01:09246d8db0406a7eefb66059e1c8e4d1c5ea419c31bc641f11ee15ecfda9f5eda9docHeodo
2020-09-14 16:39:4885b941aa2dfcdb8316fad92e43fdb207d52a3f4429b7bc59134fa759931284c8docHeodo
2020-09-14 16:24:543ab666907d1caac6699ea16ad02a0143d9478daeabc0fb3e5bd94199cb787774docHeodo
2020-09-14 15:46:22ded78c510ee2f226da8500b08b670bf12c44a6a21089ac843e7ad8f2329fd8ffdocHeodo
2020-09-14 15:37:09e42ab2c33e334aaa8d441b35ee6af4cfbf0b44d94e1a27383f436682592d0560docHeodo
2020-09-14 15:10:3786c0ce7ddf5c6e12b271984c7724e66b7b8db3ccc611a9635d8482bc01c86931docHeodo
2020-09-14 15:01:5041ce0360c56b981277f3b2de3460c5af71bffa20f9b751ab00659847c6cabb7bdoc Heodo
2020-09-14 14:40:360b783948053f5f1dadd529527bbbea3e2ed5e25f1cfa250aca3b6620aac9c26cdocHeodo
2020-09-14 14:26:563c58efa8a1ff50a1c91b091da3d10d88c300e014f0685c2d003132d3aa4b4feddoc Heodo
2020-09-14 14:07:59fb254543c44a1cd539f80a6ad686889e82942bde7aebada34cfe594da563ce12docHeodo
2020-09-14 13:48:42baaec5d00f7f89c68159655fef4d04a1aec9f20f1e49dcbdaa26c1e1ae9e185ddocHeodo
2020-09-14 13:25:52709e80f7feba536995dab42bea3297f819ef278046977ac98457c0cf63b676c3docHeodo
2020-09-14 13:12:04c2f5c771367f5e275d2d357f32e68a89f7086770c1d060600199b2f41cb0e16edocHeodo