URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-29 06:09:27 | 206.217.208.35 | host349420.mpdedicated.com | Not listed | AS48254 TWENTYI | US | yes |
| 2022-03-30 17:12:06 | 174.127.107.202 | glennsimoninc.com | Not listed | AS13213 UK2NET-AS | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2022-03-30 17:12:07 | https://www.glennsimoninc.com/glennsimoninc.com... | Offline | emotet | |
| 2022-03-30 17:12:06 | https://www.glennsimoninc.com/glennsimoninc.com... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2022-03-30 18:39:40 | afc46d6c9997ec7eff8e0790a557aca5339229db13887d493eb4e0bbf9fa20b1 | xls | SilentBuilder | |
| 2022-03-30 18:00:42 | 21cd95fb4f71525407b37a901590819a18d24ca48bd6b8f7170ff423e780dd4b | xls | SilentBuilder | |
| 2022-03-30 17:12:07 | 0976abceb9457f5a99e62acdd5004b43e5bedfca01a8f2ebf8676652a6cd23cd | html | ||
| 2022-03-30 17:12:06 | aa86d1be623622ae373fc9dcfb7365d513d0e273891e34b480ab2d7b10d6a7bb | xls | Heodo |

US