URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.behanaa.co.il
Domain registrar:box.co.il -
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-07 15:13:09 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :16

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 14:44:14 104.21.28.153Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 14:44:14 172.67.170.229Not listedAS13335 CLOUDFLARENETn/ayes
2022-01-31 15:22:13 104.21.14.129Not listedAS13335 CLOUDFLARENETn/ano
2022-01-31 15:22:13 172.67.159.41Not listedAS13335 CLOUDFLARENETn/ano
2022-01-27 11:37:44 54.145.93.118ec2-54-145-93-118.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-01-22 16:01:14 107.23.188.173ec2-107-23-188-173.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2022-01-20 21:25:19 54.224.2.37ec2-54-224-2-37.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-01-11 08:19:27 54.161.25.143ec2-54-161-25-143.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2021-12-27 07:14:40 3.80.251.74ec2-3-80-251-74.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2021-12-18 18:40:36 52.202.248.99ec2-52-202-248-99.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-08 20:05:04https://www.behanaa.co.il/get/HUyjYXUWeojRMPYIvIB/Offlinedoc emotet ext epoch4 heodo ext waga_tw
2021-12-07 15:13:39https://www.behanaa.co.il/get/rY8SEqxGp/Offlineemotet ext epoch4 redir-appinstaller sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-09 08:20:230d93a4f12d6e52dd86f8194dc522bdf7b6c4724898e929e12943c15cef4f3aa9xlsmHeodo
2021-12-09 02:50:4127eb195a0ed6e64b5b3a50fd111ddd216fd6545a3b74891745c72970cad9035fxlsmHeodo
2021-12-09 02:26:3286394057a3c827836ce89b5bbf5d4f4dafe157ae26c0afa8e2b9fd6ecb063831xlsm Heodo
2021-12-09 02:12:13957f0fab563de48ae41da020061dc0090e02cf4eaf0b022344a742105a53be99xlsm Heodo
2021-12-09 01:36:264fb3b7dfdd32dcb5f30ce1f30529aaee5a53032f3edaeaebffec25390594a57cxlsm Heodo
2021-12-09 01:26:059b73bff29b8d6a980f1250eef0616585203c83f679e6916ecd77fda273205d46xlsm Heodo
2021-12-09 01:10:598bd5b0b88997985de0e243eb068d6eef53fb8736dd2b7c3533f26fd49f7b021cxlsm Heodo
2021-12-09 00:42:41ef64d2b037e5c751a6c5fd26cdfafee6390153132f9256d7487050f9002ce3e7xlsm Heodo
2021-12-09 00:28:4647eb41ba61a62ac3714f2a4f994111c1e7954a2c79ab44eeb784863b2eb9c67exlsm Heodo
2021-12-09 00:08:289b3d2651a4e9c2fef915c86941319ac5a563c87dc5154240a4713e2bd5f985c2xlsm Heodo
2021-12-08 23:52:37e603907e9dd178e49f57d0973a342291660dd6611399e85d61966ac1fb2451cbhtml  
2021-12-08 23:47:021438301d4dcd00de6de8ccb86b00e75b7f593f2ace4b8fd843c5573d4bffba2exlsm Heodo
2021-12-08 23:27:42aefbef10d33146af2d9da6e735f8b675007af114b0cc9e0b9b7062c663f3b7ddxlsm Heodo
2021-12-08 23:06:03ad73d66c1fed4ea7dcfeff708b7deee6742c40b28ac4f16426448cbb92a1fa73xlsm Heodo
2021-12-08 22:46:5216cb000da32473ef9cd785202d6d0f3122fbdffc1e6968eb4eb27782b7908ad3xlsm Heodo
2021-12-08 22:28:464b287c609ee74dcb7f3553c412da095e5c9cb1b45938724268ad1c9c8e8be4fexlsm Heodo
2021-12-08 22:17:3217208083eaabd089802a9e38ba65b0e01c43d839cc8fc8121c5b6a343e522f7fxlsm Heodo
2021-12-08 21:45:24016b8eebcb9eb7eb1ba12b31b96df39930b75f9109507dab734104a05b50b7b4xlsm Heodo
2021-12-08 21:04:427519fc414d186985c86c04b9e28c3de909efa1f4e49125fcd3522093c69ea5a5xlsm Heodo
2021-12-08 20:40:407cf62436911434e2bf05d70f38d0bee986aa772c44655b8e3eed70df7946e5f1xlsm Heodo
2021-12-08 20:26:26bbbe9ca5ee3991cfafc9799e9dcbd1082b24c8a8219f3b0495a850c6704b753bxlsm Heodo
2021-12-08 20:09:58f6a6b64bb9ca7942e8366516c5d5c6f391eb74693eda2960e359880da8cbce71xlsm Heodo
2021-12-08 20:05:04ceffe7e0699418c10efa8fb0044044439e3c48c86e29fbfbbd491aae4a5caca9xlsm Heodo