URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: urgentsecuritygroup.co.uk
Domain registrar:Public Domain Registry -
Domain registration date:2021-08-31 00:00:00 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 09:44:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-01 18:46:03 49.12.125.113server49.hndservers.netNot listedAS24940 HETZNER-AS- DEno
2022-06-15 00:22:55 158.69.185.137ip137.ip-158-69-185.netNot listedAS16276 OVH- CAno
2022-05-31 20:35:12 95.217.120.144static.144.120.217.95.clients.your-server.deNot listedAS24940 HETZNER-AS- FIno
2022-01-11 09:44:04 95.217.199.41server6.hndservers.netNot listedAS24940 HETZNER-AS- FIno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 19:38:04http://urgentsecuritygroup.co.uk/xjwn/wlaYOIv6K...Offlineemotet ext epoch4 macro xlm FplPhoenix1
2022-01-11 09:45:04http://urgentsecuritygroup.co.uk/xjwn/wlaYOIv6K...Offlineemotet ext epoch4 heodo ext SilentBuilder xls Cryptolaemus1
2022-01-11 09:44:04http://urgentsecuritygroup.co.uk/xjwn/wlaYOIv6K0I/Offlineemotet ext epoch4 redir-doc xls waga_tw

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 04:55:55aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdxlsHeodo
2022-01-12 04:40:1558c5a48579e8499ec3aa409ee960a020592e422516e0aaa2847880ca43f84e90xlsSilentBuilder
2022-01-12 04:20:24dd29267f0e261f6e92659d05355be93a6ab0c1e4a43501711cb9cb20d384f04dxlsSilentBuilder
2022-01-12 03:38:09e32f0c4a46eb1839845394810bef1e5fa06054e8372e74ad442da3d8b5325475xlsSilentBuilder
2022-01-12 03:08:56aa0e36780912b94ce9abefe196de12d6f4097dbc7fa864d24778638043de4084xls SilentBuilder
2022-01-12 02:49:56d7638004f7dc1a884abf073a6c04d5d205ba31f4d66800216ddc303dd3f41249xlsSilentBuilder
2022-01-12 02:22:34c468d97804e7a9fa569cfab4952c6fda72685adc622cec8aee02bb9c8f1a79aaxls Heodo
2022-01-12 01:43:42813438ff7ef652ea23e922f8a5e61c7f14ec49b270546d3ce47f66161707cc03xls SilentBuilder
2022-01-12 01:27:02ecaa8fa10f2e5726552f68f4c691133bb782d791b23c96e2c26b5c4838a00e68xlsSilentBuilder
2022-01-12 01:02:44894ae1ab382fe85d09096d1997f468b8e5f327326c39e15bd1ba47f4c4d2f14fxls Heodo
2022-01-12 00:30:05fb59d08c1c00da6e08768d759d984922ef2726cade6ed27fe5713a79e7b7022exlsSilentBuilder
2022-01-12 00:02:581bd3d0d3bef771b182e3de5670d6f9515c73b76cf971203cccba88fb2dd3ddbbxlsSilentBuilder
2022-01-11 23:54:494e4fed9bc0e99667d6959b4513a5c89a5f76f2437b19ae6b5b8c3ff15ba2b71cxlsSilentBuilder
2022-01-11 23:17:42a7fe36211a0be63df4c3929830b8fc4e21fc0548b5446377ce9c83b3d1fd9339xlsSilentBuilder
2022-01-11 23:01:47207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349xlsSilentBuilder
2022-01-11 22:42:199b3fb2f88edc75661d9aba9ccac4bd15607dbf2fa7542c47be3d533c0db5cbe5xlsSilentBuilder
2022-01-11 22:17:1514222deeec10d32091a2947e045833bd25c041a662f4090df26e50381cf922c6xls Heodo
2022-01-11 10:57:087cdaadfceae5a41f40a2981e46f0c03a16496610c54c5a2adc39d51cbe56e535xlsSilentBuilder
2022-01-11 10:37:20170593f29ae9e0eabaf7a2bea5add079c8cf136163cdbbbdc5e791a30006031dxls Heodo
2022-01-11 10:15:51fd9f32d79ea98273f97ea6c36042a4f43ee66720751a3e650eaa6f3f5e2dcbd1xlsSilentBuilder
2022-01-11 09:55:087eaad9ed201034aea3621c5ff8a3517046e4136ee73fce516b1bfcfbdd4fdea3xls Heodo
2022-01-11 09:45:04416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dxlsSilentBuilder
2022-01-11 09:44:040a829f6c2294230a41723892b9f28f99c84cdcbbf70dcbfaf6833d2aec44acf9html