URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.behold.io
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-28 15:29:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :17

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-30 05:07:48 65.8.131.65server-65-8-131-65.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-10-30 05:07:48 65.8.131.55server-65-8-131-55.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-10-30 05:07:48 65.8.131.45server-65-8-131-45.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2025-10-30 05:07:48 65.8.131.39server-65-8-131-39.fra60.r.cloudfront.netNot listedAS16509 AMAZON-02- USyes
2021-01-28 15:29:05 178.79.148.49li268-49.members.linode.comNot listedAS63949 AKAMAI-LINODE-AP- GBno
2025-08-27 04:16:07 18.165.183.10server-18-165-183-10.zrh55.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-08-27 04:16:07 18.165.183.110server-18-165-183-110.zrh55.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-08-27 04:16:07 18.165.183.35server-18-165-183-35.zrh55.r.cloudfront.netNot listedAS16509 AMAZON-02- USno
2025-08-27 04:16:07 18.165.183.41server-18-165-183-41.zrh55.r.cloudfront.netNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-29 16:16:03https://www.behold.io/bin_jzbvYfwP234.binOfflineencrypted GuLoader ext abuse_ch
2021-01-28 15:29:05https://www.behold.io/bin_mmLEXbL125.binOfflineencrypted GuLoader ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-28 15:29:047879745a569524f376df858aa6095cdbb33580b6f8373363200492abfe3feee7unknown