URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 11:43:05 | 138.117.103.55 | 138-117-103-55.cliente.imicro.com.br | Not listed | AS262387 Intermicro_Ltda | BR | yes |
| 2025-04-27 11:43:04 | 187.50.159.26 | Not listed | AS10429 TELEFNICA_BRASIL_S.A | BR | yes | |
| 2025-06-10 06:23:42 | 191.36.194.116 | 116-194.36.191.in-addr.arpa | Not listed | AS263339 3WLINK_INTERNET_LTDA | BR | yes |
| 2025-04-27 11:43:06 | 191.36.194.202 | 202-194.36.191.in-addr.arpa | Not listed | AS263339 3WLINK_INTERNET_LTDA | BR | no |
| 2021-01-13 00:50:35 | 104.21.5.179 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2020-08-25 21:44:16 | 172.67.133.177 | Not listed | AS13335 CLOUDFLARENET | n/a | no | |
| 2020-08-25 21:44:16 | 104.28.12.91 | Not listed | AS13335 CLOUDFLARENET | OM | no | |
| 2020-08-25 21:44:16 | 104.28.13.91 | Not listed | AS13335 CLOUDFLARENET | TK | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2020-09-21 05:27:36 | http://www.closmaq.com.br/wp-admin/nc/ | Offline | emotet | |
| 2020-09-18 08:39:07 | http://www.closmaq.com.br/wp-admin/public/3HZDD... | Offline | doc emotet | |
| 2020-09-16 08:45:08 | http://www.closmaq.com.br/wp-admin/Scan/ | Offline | doc emotet | |
| 2020-09-14 07:05:26 | http://www.closmaq.com.br/wp-admin/browse/ | Offline | doc emotet | |
| 2020-09-03 19:02:05 | http://www.closmaq.com.br/wp-admin/INC/gzj7zw/ | Offline | doc emotet | |
| 2020-08-28 08:39:36 | http://www.closmaq.com.br/wp-admin/INC/fci836-0... | Offline | doc emotet | |
| 2020-08-25 21:44:16 | http://www.closmaq.com.br/wp-admin/swift/ | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
BR
OM
TK