URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.almusafirholidays.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 05:57:06 UTC
Total malware sites :1
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 20:18:20 101.46.57.249server.almusafirholidays.comNot listedAS136907 HWCLOUDS-AS-AP- SAyes
2020-11-24 16:47:42 95.216.186.65server.almusafirholidays.comNot listedAS24940 HETZNER-AS- FIno
2020-10-30 07:32:38 95.211.252.211Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2020-10-21 05:57:11 63.250.36.225nc-ph-2543.mega-glass-moma.comNot listedAS22612 NAMECHEAP-NET- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-21 05:57:11https://www.almusafirholidays.com/new/swift/hjc...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-21 18:01:14c3caf9f914df7b8d90ac3dd35fd1ad24ec34a4d1af94293e9002a9f8f943703edocHeodo
2020-10-21 17:37:06cb128eb8a7e2118942b9dc0b429a21c8aa057dac01473ad072f487d02cc80849docHeodo
2020-10-21 16:57:42c92778df4ae556cc2ad66979e6fafa9256ce4c9c7d0457c6525711429def55fedocHeodo
2020-10-21 16:20:574d2ca163c6d59789cde935b7d539ba3c8e4abd2beed45704fba11fe67fc983a2docHeodo
2020-10-21 15:59:17801d055e1eedecef11caac3bb1c618c0699c6f601404d03fcb2d2b1421c3b03cdocHeodo
2020-10-21 15:04:23a8e0958e9f5cc471c0d6f5e23d002544d61929844383b17429c383146a68911cdocHeodo
2020-10-21 14:28:0327a0f68aaff44c4e5adb18dd89c4cb3b92fa305b84cd9bdfd76c9a5d8dbf58f1docHeodo
2020-10-21 14:22:21d5c24aea94acf1b51e67dc57eaeb7009e54b212f508d33e9c08beba932daaafddocHeodo
2020-10-21 13:39:43a22de608c25a6a0dec4ca2749b1a1048b8351177b5195780f85baaee421ce713docHeodo
2020-10-21 13:08:46a002bd15074effe4548ccc07946e51276be1d1ffbdbe1e474aa78b2f629a997cdocHeodo
2020-10-21 12:49:00cd8851bd896a7e87cc70c70d34d548cf3618138a015fc11eec546d47780a586ddocHeodo
2020-10-21 12:17:138cfa219330a7e68795a29e761cb2e73a2dce4884afebba4f91a0886dc8012920docHeodo
2020-10-21 11:54:207fd4239f8f25bb0287746f554cbdffc534ced3346467f2a882722772a9d44d34docHeodo
2020-10-21 11:28:2464c0402c0b906a218b1e4c2101145066a57b5a034a16a82957081f8ca15b4763docHeodo
2020-10-21 10:44:19ca0fddb21291a2fc5f13391576cdc877b2748934257b1294142481e3a734cd47docHeodo
2020-10-21 10:00:49552e98ed18af24b89d6cd937f335ee85312e919ad186a6e0d1bb5839fdc96167docHeodo
2020-10-21 09:57:51e88388bec3164944678627db062b753e76b6f7f710a9fabc43dfe69e7df2f366docHeodo
2020-10-21 09:04:38d3eb1ac711c92a7ffd2516e93813ce184cf849bf5cc7890aadab90c20f450c17docHeodo
2020-10-21 08:47:4191b4636eaefca65ce60c334d8ae4d9c2b01b86dab6e1aa54127de53228272d88docHeodo
2020-10-21 08:31:55e6335af6ecbbb9d05de5332fb55088045d8066babe6f9fb4cb05e7097ce44046docHeodo
2020-10-21 08:09:15453c4b4cf3a5fda7d48005d020112c06ebcbcf478ead4ebcfacf25576781bb2adocHeodo
2020-10-21 07:35:187bb0c64469d6f91a86db62a275cfbfa0b6bbf04e10bde77f507649c0adbd844adocHeodo
2020-10-21 06:46:25f6ca28aa0ec1ee28ce246d787de062e5b78554ec2cfc62fbf00db085c177b074docHeodo
2020-10-21 06:05:5439a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343docHeodo
2020-10-21 05:57:11fdf5102af9db589345a5c7d4e747c98489a7341147058b2a42e337a03fa62baadocHeodo