URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-10-16 13:24:10 | 13.248.213.45 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-10-16 13:24:10 | 76.223.67.189 | a67c48129651a0940.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 15:25:26 | 15.197.148.33 | a2aa9ff50de748dbe.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2025-04-27 15:25:26 | 3.33.130.190 | a2aa9ff50de748dbe.awsglobalaccelerator.com | Not listed | AS16509 AMAZON-02 | US | no |
| 2019-12-05 14:48:55 | 148.66.152.34 | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | SG | no | |
| 2019-01-23 06:48:34 | 160.153.60.104 | 104.60.153.160.host.secureserver.net | Not listed | AS398101 GO-DADDY-COM-LLC | US | no |
| 2019-11-15 06:19:42 | 184.168.221.81 | 81.221.168.184.host.secureserver.net | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | US | no |
| 2019-01-22 09:33:22 | 166.62.28.100 | 100.28.62.166.host.secureserver.net | Not listed | AS26496 AS-26496-GO-DADDY-COM-LLC | SG | no |
| 2018-12-21 07:50:16 | 146.20.148.230 | Not listed | AS27357 RACKSPACE | US | no | |
| 2018-07-12 02:38:07 | 132.148.220.95 | 95.220.148.132.host.secureserver.net | Not listed | AS398101 GO-DADDY-COM-LLC | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2018-08-22 22:25:57 | http://www.miniconsultancy.in/FILE/En/Past-Due-... | Offline | doc emotet | |
| 2018-08-21 08:00:43 | http://www.miniconsultancy.in/FILE/En/Past-Due-... | Offline | doc emotet | Anonymous |
| 2018-07-26 03:58:14 | http://www.miniconsultancy.in/DHL-Express/EN_en/ | Offline | doc emotet | |
| 2018-07-17 21:36:30 | http://www.miniconsultancy.in/doc/US_us/ACCOUNT... | Offline | doc emotet | Anonymous |
| 2018-07-16 07:53:38 | http://www.miniconsultancy.in/default/EN_en/ACC... | Offline | doc emotet | Anonymous |
| 2018-07-12 02:38:07 | http://www.miniconsultancy.in/doc/En/Jul2018/In... | Offline | doc emotet |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2018-08-22 03:28:04 | 78f489ff158b9383ff9452fb42f0e318c8dc04c1dd93e3c4f4ee69eeca4e0919 | doc | Heodo | |
| 2018-07-19 06:24:56 | 5da441a5129f4d0cb8ab72d45b985fb9238218eee413835e1c6d94686fad9d5d | doc | Heodo | |
| 2018-07-18 06:51:34 | e7db2087ef7f0f80640c7f62a493da43eadb8db5f5af90ef1cb55e68a465696a | doc | Heodo |
US
SG