URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: sharkrigs.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-23 22:57:05 UTC
Total malware sites :1
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-03 23:52:23 13.248.169.48a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-05-03 23:52:23 76.223.54.146a904c694c05102f30.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USyes
2025-09-05 18:52:40 166.117.110.61Not listedAS16509 AMAZON-02- USno
2025-09-05 18:52:40 99.83.161.153a2b7bf3398455f345.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2022-12-01 01:02:37 104.253.151.113Not listedAS3561 CENTURYLINK-LEGACY-SAVVIS- ITno
2021-12-09 00:35:48 166.88.79.113Not listedAS212238 CDNEXT- PLno
2020-09-23 22:57:06 188.64.184.197grape.ukhost4u.comNot listedAS47625 UKHOST4U- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-23 22:57:06http://sharkrigs.com/sys-cache/DOC/e1xvc3cryry/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-24 08:38:46b0c9e63cd039da312aea84e7c632e4faab8fa1bf3b6d8382f6fd898635c39941docHeodo
2020-09-24 07:14:1069ff6eb0a71090b17e21b2829b6108b2eebf8bd12b92fe587ce103a4c5cc0f3ddocHeodo
2020-09-24 06:41:13fe0a0b77df06046dffc8059552a1484dfa263360d127d452805142945aa4e5a8docHeodo
2020-09-24 06:26:12e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04docHeodo
2020-09-24 05:53:40d522d2f16aa3e16dc127e4340ff8bfd23ab4de894995c8dbb75b31bd4b4d73cbdocHeodo
2020-09-24 05:38:51a92504d33c04f21f1e8bfc2322f66cf3d45f486ed7ebbf78f3ee270fb0d3e3a2docHeodo
2020-09-24 05:31:31a92c46f200df0158c9798071b11a95d81eea54126f75084d6b9b381d992d4d0cdocHeodo
2020-09-24 05:03:5721d6462af9e28cac11c5b8bc20c9f07e953c7af99c15966175e8b8cfc8ee9363docHeodo
2020-09-24 04:30:16353903d7b90942b9e45059e7a1ea56eea91c412f5cf0864982870f55f9e61e98docHeodo
2020-09-24 04:11:18813c3689cf9fecd602a950034dcd90f060f360f68193e239a02e13ed8587c220docHeodo
2020-09-24 03:47:063f165297835a1afd80d7c9fcf087b03e04dd420e6e747ae16a5d0cb6da8eaa97docHeodo
2020-09-24 03:25:433b95077a69ba1ee1226face3a5f83a78950357b93815180ebb6b6772cf8212e8docHeodo
2020-09-24 03:04:053e64351afeaa45724ba4e119f792781b8f1e311623e056e6c7f2f27f2ee9cc5adocHeodo
2020-09-24 02:35:438c2167e0297ffcef1e67f0aed9f87dd7de95a4b552865584b7bd0185ac8f98f9docHeodo
2020-09-24 02:03:4080bbc6addbc3d97abecb341c4441b7963d70a2a863d25cf0d35137632a841fa4docHeodo
2020-09-24 01:34:56098e0c52d47feef3ad6ad20535919541c76799f4bddd67233049509a0ae8656ddocHeodo
2020-09-24 01:26:276e7ae3df631cfa3174a4e9e061f71a3453806fe930adca05896343d9e6f07ea4docHeodo
2020-09-24 00:46:34a6bdea3758ccb519e3736628a467290a74b47562f8a489e89346642276c9f177docHeodo
2020-09-24 00:37:450e30a7bc2d19a489b6c26b22e411e9f691cfb0b9d693a5888ae064519809470cdocHeodo
2020-09-24 00:03:57b3d57ca8076070443526c2cb24b0a0ec82bdde3df2573290b884425536b600b6docHeodo
2020-09-23 23:45:46bad24e6bdf40e58be83bdeb717bcb1a09ae986e50f8c51fdc11ff8de777a4482docHeodo
2020-09-23 23:26:501c5a69e8a8d964a5898cedf16872a9903fcf2ec9f08ce3ecd9510f8d4453c4b9docHeodo
2020-09-23 22:57:0613b44fe04aec7fdc7dce67de3a987317ad25ab9301110382847ca08bd645f2bedocHeodo