URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-29 05:57:54 | 15.197.204.56 | a3edc0dabdef92d6d.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2025-04-29 05:57:54 | 3.33.243.145 | a3edc0dabdef92d6d.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | yes |
| 2020-02-27 16:47:06 | 5.9.240.69 | static.69.240.9.5.clients.your-server.de | Not listed | AS24940 HETZNER-AS | DE | no |
| 2020-01-29 21:06:03 | 144.91.91.254 | vmi1339480.contaboserver.net | Not listed | AS51167 CONTABO | FR | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-01-29 21:06:03 | https://startupdigitalservices.com/cgi-bin/priv... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2020-01-30 08:50:19 | 05540ab9749b214e8557c647443d6b4f997326d9e3ec01cf69b855c519c53887 | doc | Heodo | |
| 2020-01-30 07:59:45 | cbfd00a796bdd447134f7dc1f38823e8e2eefb7075068cc197ec67c044ecfc24 | doc | Heodo | |
| 2020-01-29 23:38:19 | 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254 | doc | Heodo | |
| 2020-01-29 22:07:27 | 315cf86a77ccf32952f4878001e53336340ba0103585421695ee79ae25153bea | doc | Heodo | |
| 2020-01-29 21:06:03 | 298bc64aeae7a7fee709c9e23cb3a4c707ca801f8ae68589f33ed024f70b2b53 | doc | Heodo |
US
DE
FR