URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: vaporizer.shopping
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-26 12:58:03 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 22:35:53 49.12.86.51myadmin.vapoclouds.comNot listedAS24940 HETZNER-AS- DEyes
2020-12-31 12:21:24 18.158.103.3ec2-18-158-103-3.eu-central-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- DEno
2020-10-26 12:58:04 188.138.17.14atlantic475.startdedicated.comNot listedAS29066 VELIANET-AS- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-26 12:58:04https://vaporizer.shopping/wp-content/u/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-26 13:55:57a63c502e6b17dff5564bd862d8f81577c7311ae759e5dd3a63e9ad5e91071a40docHeodo
2020-10-26 13:33:184b1547415d334829daf8667917db64ab56ce678a7b27f6e3fc08f342ad6fae73docHeodo
2020-10-26 13:26:10456eb2b478caa00b10e1c06ca22eab8d9cc7a130334049be232b800a32d5d005docHeodo
2020-10-26 12:58:046fcf56298eff120bfc74ce76dff94bb46847c28367b496ce17e744119a36ee2edocHeodo