URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | shift2digital.com |
|---|---|
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Not blocked |
| AdGuard : | Not blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Not blocked |
| OpenBLD : | Not blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2020-10-21 14:20:03 UTC |
| Total malware sites : | 2 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 2 (100%) |
| A record(s) observed : | 15 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-24 22:43:27 | 13.223.25.84 | ec2-13-223-25-84.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | yes |
| 2025-09-24 22:43:27 | 54.243.117.197 | ec2-54-243-117-197.compute-1.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-08-07 21:31:14 | 52.201.53.166 | ec2-52-201-53-166.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-08-07 21:31:14 | 98.82.42.139 | ec2-98-82-42-139.compute-1.amazonaws.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-07-29 02:53:16 | 44.213.46.149 | ec2-44-213-46-149.compute-1.amazonaws.com | Not listed | AS14618 AMAZON-AES | US | no |
| 2025-05-14 20:09:41 | 13.248.213.45 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-05-14 20:09:41 | 76.223.67.189 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 18:14:10 | 46.202.186.43 | Not listed | AS47583 AS-HOSTINGER | ID | no | |
| 2021-04-08 15:30:35 | 141.136.39.81 | cpl14.main-hosting.eu | Not listed | AS47583 AS-HOSTINGER | GB | no |
| 2020-11-15 23:33:02 | 204.93.169.73 | mocha3032-web.mochahost.com | Not listed | AS23352 SERVERCENTRAL | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-10-28 05:41:05 | https://shift2digital.com/wp-admin/Overview/sn7... | Offline | doc emotet | |
| 2020-10-21 14:20:06 | https://shift2digital.com/wp-admin/XadQ7ov8Exxo/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-10-28 06:09:04 | 771cbbf0ba54f218c39a1aabe10c9c1653a1b59a863047a561bd2a9068c9eb6b | doc | Heodo | |
| 2020-10-28 05:41:05 | 25a38466146889f4833a21d4be2e6863c6f4617e632f0bc33436d7023cbaf734 | doc | Heodo | |
| 2020-10-24 13:29:45 | 64d785d18d4dd4904a4ea1c9d9493cfc2e7cbae4856956062bcacda90ddbbe02 | doc | Heodo | |
| 2020-10-21 15:00:55 | a1d14cef317aece443bc010579448ed548c495541c8540cf423fc5f1d8a20fe7 | doc | Heodo | |
| 2020-10-21 14:20:05 | eaeb4f164378a43e002228ed077d1ca35b642392aabf44539258434ce3a8ae20 | doc | Heodo |
US
ID
GB