URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: twentyfour.co.il
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-16 13:54:33 UTC
Total malware sites :1
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 20:13:46 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 20:13:46 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2020-12-26 19:42:35 62.219.78.101Not listedAS8551 BEZEQ-INTERNATIONAL-AS- ILno
2020-10-09 10:48:27 35.246.200.101c5.vangus.ioNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2020-09-16 13:54:34 13.248.216.115ae6ffc1ed6fe16d44.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-16 13:54:34https://twentyfour.co.il/test/docs/osE1hYiMxXkb...Offlinedoc emotet ext epoch1 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-17 09:09:307bf316c85c4d21cd3cf7dfbfaa10e44484322e4697b8783838b3dbd3ef225a2fdocHeodo
2020-09-17 08:51:4060b7c0ca863b5e725fef0972fe2b8f961fef11d410535b9c1a4cbafe12684497docHeodo
2020-09-17 08:33:051d0eb0bcc259726383e2d351d1fbcfb5cfd92fce33941766914bd0c987b85f81docHeodo
2020-09-17 07:59:25ee9bf2f3b61b6d28c5bc8efd4fc0ec22b9e726913c0827f421de885700c2abeedocHeodo
2020-09-17 07:50:243efda29907b74c348feb380198e81f82dfe13f13cf585d8738dc6a8d134ddafddocHeodo
2020-09-17 07:29:352cb207ab66e30c595eca873c8715faa371afeba1dd6ba8465e08029c874dc812docHeodo
2020-09-17 06:56:1821625460051d884ab1a873d7dcf891f3b5a6672d35a8fead960161cdaa8ca94cdocHeodo
2020-09-17 06:41:44e60fedb3fe078220df81cb794e6309555223d7b6024c1566ce99b8518840c396docHeodo
2020-09-17 06:25:50254a33e1b25338514edd5ba6d1d64f958a599a411ae5e53777ac52cc6aee8258docHeodo
2020-09-17 06:04:530dbad315cddc667cb29f30d02de18c3d5ff0547e0814c5170510ba1a11766b7adocHeodo
2020-09-17 05:34:341f78ddc5ed3c3410d1dae6bbdf7801d065a07f11d652a3275d86939253a064c0docHeodo
2020-09-17 05:22:28ffd80122044b9108a17b1c9f057aaea0d1baae187063fc22c16db963a2b71e3bdocHeodo
2020-09-17 04:57:18530fccb7e7dd4a6fbb7cad9093452f103e951bcfb762d58889a98ce7a5bb785ddocHeodo
2020-09-17 04:38:3735088b84f2026bcbde876c9c9188d18287ccaf07b304b1fa9910f476c7aa36a7docHeodo
2020-09-17 04:12:3784c4bededfcf319c65e87c3d55ebeec4d882c316c89e9716e5c29b9cf37a1821docHeodo
2020-09-17 04:04:56b65fc0d82786a15ce9e6a028e521d79621c24ceae0da0ec61aeb703ed6921e94docHeodo
2020-09-17 03:35:389d74d4c490b8d1894ba95fece089f3917ca557122da591a3176f6e8bb182a926docHeodo
2020-09-17 02:43:588276711c50ee244236dd639fa767cd234f01e188f32bbe46b1ab5933a2e7a85cdocHeodo
2020-09-17 02:33:43a10287b95075632ae5434563b27c8d5040127c955643bc255f9b617834969547docHeodo
2020-09-17 01:48:4052d1e34446e3375a5113383a78e7bc3a0a6c4a1791c2ef347e56564217852ca0docHeodo
2020-09-17 01:36:17e778b3db0521e8c8b9f7429eeaafee991bca2bca736c3a9330e0252dda698f66docHeodo
2020-09-16 13:54:347970fcfdac90cf00463cbe1bd52b65de61382f75f5fbe7bdfd457aea3893e244docHeodo