URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: wellmd.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-05-02 11:31:02 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-09 12:58:37 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-11-09 12:58:37 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-28 09:54:12 66.235.200.145host77.ipowerweb.comNot listedAS13335 CLOUDFLARENET- USno
2019-11-08 14:16:11 146.66.66.253ip-146-66-66-253.siteground.comNot listedAS13037 ZEN-AS- GBno
2019-05-02 11:31:04 66.198.240.88.240.198.66.in-addr.arpaNot listedAS55293 A2HOSTING- USno
2025-11-08 11:17:24 54.82.199.115ec2-54-82-199-115.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-05-02 11:31:04http://wellmd.com/wp-admin/SJSYwQyghaqk/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-05-03 17:21:4146dddf743200acba21e4e2eadf9567769446002f19b405be24576832b3cd1888doc Heodo
2019-05-03 01:42:32990801c1de058647b506c19565ee7abf0c886af33defe87c185c91aa65f9b579doc Heodo
2019-05-03 00:56:348217083c9e4b5ff7f2e438a2e50d8fbc5f75cd170801dcbd6bf1592b4ee6e76edoc Heodo
2019-05-03 00:18:37f268669cf7822cdb42f9407a39e23549e79930c64deabf9fb45acb7c33aca728doc Heodo
2019-05-02 23:48:32f38d5609ce63487e3e63cdd748f198d3e2afff98ee43ed99880ccac6a883d3b6doc Heodo
2019-05-02 23:02:30aebc1103f9344e4926c8904a4f9a6eaa1edcae4a8eb2fcdf5c19d535737a0b57doc  
2019-05-02 22:15:30354a0c17e9b347d1d27a3b8d605f7f1bf162d5ed17453430d9bd70ad026da3a2doc  
2019-05-02 21:38:284a4e5f7221b64a94e9ef4e6aa74464802d5156b0fed3258d36bc778233fbf8aadoc  
2019-05-02 20:54:296c1d9bbd9dcad8b950dcada8139a8b21e31036ae9d319050f7513d240ef31995doc Heodo
2019-05-02 20:07:26abc589d5ec63138ee0c588f744cb6c8ba59baed47e9316419c174ef6e6a7e393doc Heodo
2019-05-02 18:33:2477097aa9879009420abd97243ad99b01d6f37aeb4a0f10db935af76d24071f60doc 
2019-05-02 17:46:220a0052896d023efd6db21fdb504e996474df83abcfe4ffb55b55bfd894125505doc Heodo
2019-05-02 17:16:19592706d46283eeff5a73e3bc816333334ae78f9d1f8162cc5517f402646e8f71doc Heodo
2019-05-02 16:45:2811f45c2f0d6d243306cbd6c70c01f1efb2050836b14f4d669b7a471511ade739doc Heodo
2019-05-02 15:12:0961363331b4ed5c211a5108f4820e0e7b31451bb9fb50da87d537b88e01159528doc Heodo
2019-05-02 14:36:143c37cb5bc7d34a299c3442b5d9877e8f4932af1dd6ca5a8b139a668fed5f9786doc Heodo
2019-05-02 13:11:10d208f3eff68d5739131aeb2b16c66c1b6afb8fae27517f1b7b9029d4ef8b1ce2doc  
2019-05-02 12:31:07a64dafa37b662494a38730bcc5e028b2531be116573db369d5afc8d881e33f8ddoc Heodo
2019-05-02 11:46:118715b1a0fca07aa174dff8f761755d3879f305b1c5201960fda42ed8840822aedoc Heodo
2019-05-02 11:31:04ba194c165790fe37e147a5148a0e460acbf65bdbafbf0928bc1bd762359e0691doc Heodo