URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-19 21:56:27 | 104.21.67.62 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-11-19 21:56:27 | 172.67.214.253 | Not listed | AS13335 CLOUDFLARENET | n/a | yes | |
| 2025-11-17 18:01:05 | 185.253.212.22 | Not listed | AS48707 AS48707-OPS-PL | PL | no | |
| 2025-04-27 10:38:54 | 69.57.162.29 | premium267-3.web-hosting.com | Not listed | AS22612 NAMECHEAP-NET | US | no |
| 2018-06-29 04:44:34 | 31.0.208.139 | apn-31-0-208-139.static.gprs.plus.pl | Not listed | AS8374 PLUSNET | PL | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2018-07-16 10:20:15 | http://www.bagiennanarew.pl/libraries/UFZYuWwNM/ | Offline | emotet | Anonymous |
| 2018-07-12 05:50:30 | http://www.bagiennanarew.pl/plugins/Zahlungssch... | Offline | doc emotet | |
| 2018-07-05 23:43:04 | http://www.bagiennanarew.pl/modules/mC613HtOWI/ | Offline | emotet | |
| 2018-07-04 05:04:25 | http://www.bagiennanarew.pl/plugins/EN_en/INVOI... | Offline | doc emotet | |
| 2018-06-29 23:57:34 | http://www.bagiennanarew.pl/cli/Abierto-Pasado-... | Offline | doc emotet | |
| 2018-06-29 04:44:34 | http://www.bagiennanarew.pl/media/lRmhD1/ | Offline | emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2018-07-12 12:22:49 | 1a5eaa3b8261f0a77136d36fc1f93e9df5a4cb982b68ed8419ec23c06b961270 | doc | Heodo | |
| 2018-06-30 08:34:32 | 027c6eff88fad90897f116eb96b21980bdf0d89f36f72df4960726e3334331c6 | doc | Heodo |
PL
US