URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-05-03 02:03:22 | 195.110.39.222 | sky.afaghhosting.net | Not listed | AS48715 SEFROYEKPARDAZENG-AS | IR | no |
| 2020-10-14 11:36:52 | 45.156.184.40 | light.parsvds.com | Not listed | AS208161 parsvds | IR | no |
| 2020-08-18 07:24:10 | 87.236.215.153 | ip-87-236-215-153.hosted-by.parsvds.com | Not listed | AS208161 parsvds | IR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-08-18 07:24:10 | http://simayezarand.com/agpekft/private_8323439... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-08-18 09:26:15 | 63fc7bb7b01996cde65e632380bdd0c32da6c7245e64b85e45bcfcb4fb5e0af4 | doc | Heodo | |
| 2020-08-18 07:54:15 | b1a5b0c45a385a514d7ee49f36e2df92b90949faf44927ad0a6540f39686a5f4 | doc | Heodo | |
| 2020-08-18 07:35:44 | ca13f800b50bf58a4b795fc6da781783074ec311cdcf92e79eefffd9b952747d | doc | Heodo | |
| 2020-08-18 07:24:09 | f772d8c5c470171c274950041849658441510dcfc5c204154479b17ef410584c | doc | Heodo |
IR