URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.bat.archi
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2019-05-15 19:31:39 UTC
Total malware sites :1
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 14:27:08 3.167.227.12server-3-167-227-12.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-04-27 14:27:08 3.167.227.23server-3-167-227-23.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-04-27 14:27:08 3.167.227.31server-3-167-227-31.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-04-27 14:27:07 3.167.227.83server-3-167-227-83.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-07-01 09:38:05 65.9.66.3server-65-9-66-3.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-07-01 09:38:05 65.9.66.48server-65-9-66-48.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-07-01 09:38:05 65.9.66.6server-65-9-66-6.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-07-01 09:38:05 65.9.66.88server-65-9-66-88.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-05-26 03:31:04 18.66.112.26server-18-66-112-26.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-05-26 03:31:04 18.66.112.27server-18-66-112-27.fra56.r.cloudfront.netNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-05-15 19:31:43https://www.bat.archi/wp-admin/lm/bw0n1svwvd8sh...Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-05-16 07:14:113257cfc9caf85ca8dafb76c69f6c2744b33cd46b7d9b119fdddd78694848d358doc Heodo
2019-05-16 06:45:11f3ca34c834bd72132b1bbf778221ca2fc9afe5376e8ae63e554da272aeacee74doc Heodo
2019-05-16 06:21:206665273fb05925bc755b1ee27eb962d49991f2d7926821ac019bb89a3384f745doc Heodo
2019-05-16 05:52:1137a8f9312cbc6314a69d480c19287b0c41de1f346a301d0d9e07d95da178b94ddoc Heodo
2019-05-16 05:25:14dc6a4d64f801a9d61cca7c938966ebcfd8d527cbf7f8cdf4410ab757e57aafe1doc Heodo
2019-05-16 04:55:158694de480619ef8cb16e017eeffd8039c54cd006039877cc654992e24a3fb419doc Heodo
2019-05-16 04:14:12ec44be0b3814bf8c733fc21a96d495683d66e1d53b4e9cb34316c08877bf90c8doc Heodo
2019-05-16 03:45:1147413a4ab923acaf1bb2ac8eccfd9a1a66d282fa0b3731ddf2d062bcc2b58f70doc Heodo
2019-05-16 03:03:1009e81da7bfaa218857aa72793b86b2f3d3d4fd102e4282702bd524c45428833cdoc  
2019-05-16 02:38:11ba86bb5815a08535c4003977676bf6bd54908b0d89cfa49df3da74aadd0ac6afdoc Heodo
2019-05-16 02:13:20f18a0f8516c937674a301ccfb5111a009e5621a31e4036af25ae97470626b3e0doc Heodo
2019-05-16 01:47:06acec5b482ad5a4de84e5e7f3146c7e04131d0a04b6874d552f33a97812fc9e38doc Heodo
2019-05-16 01:01:189b7e99499d0dcd4959e69800de74b8356b9ce5da4fc2e5897c3edfcead8bd8d3doc  
2019-05-16 00:40:23d3d69226a3f6759d15a4b94a3ad99da3e20a28113194cff91dfe345c1696a7a9doc Heodo
2019-05-16 00:12:34942c724bdf60dba3fad9f8695be9b19d96df15a8314d35fd82055b62610f62cddoc Heodo
2019-05-15 23:25:224821d11f5f6c1d360fb783467ccf365e9e9d412b9d63e262004e592bf8083d03doc Heodo
2019-05-15 22:38:15d29f6030fc82c182401170d9f7c16805011d26e3b2e6517be9329aac5f76eab8docHeodo
2019-05-15 21:53:163a26799b284110e4dbb03656850eb1dd8ccbf78f1c4ef641d980668649994c3edoc Heodo
2019-05-15 21:24:10fdf0e5c1d38c12d7877c65b2bb16aaedf41cd907636554ef9eb7d372bd647fa4doc Heodo
2019-05-15 20:55:14e61ecdeb7d0d5e709511bf3a05f93ec484b55209dab718cf51d22579be2d711adoc  
2019-05-15 20:08:113e7c9a76109feaa7e7d079401d59530c4685c532a45521c8665462efca4a7e71doc Heodo
2019-05-15 19:31:42ede61ea068666c707af52a910a2867ac9056b307e44e67c879525ac6d9e16e3edoc Heodo