URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.sundayplanning.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2018-07-20 03:45:51 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)
A record(s) observed :20

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:14:19 104.21.50.54Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 09:14:19 172.67.201.140Not listedAS13335 CLOUDFLARENETn/ayes
2019-07-21 06:45:39 54.95.148.24ec2-54-95-148-24.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-07-26 04:19:36 13.114.128.73ec2-13-114-128-73.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-07-21 06:45:39 54.248.185.239ec2-54-248-185-239.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-04-09 18:16:58 52.198.50.41ec2-52-198-50-41.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-04-09 18:16:58 13.114.62.150ec2-13-114-62-150.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-04-08 18:08:44 52.196.149.188ec2-52-196-149-188.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2019-04-08 18:08:44 54.65.191.22ec2-54-65-191-22.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno
2018-10-23 06:03:55 52.194.49.69ec2-52-194-49-69.ap-northeast-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2018-08-31 15:36:09http://www.sundayplanning.com/2sOfflineemotet ext exe heodo ext unixronin
2018-08-24 08:33:39http://www.sundayplanning.com/8739UIW/SWIFT/Per...Offlinedoc emotet ext heodo ext ps66uk
2018-08-24 04:39:44http://www.sundayplanning.com/1376TICV/SWIFT/Bu...Offlinedoc emotet ext heodo ext Cryptolaemus1
2018-08-22 08:52:12http://www.sundayplanning.com/1376TICV/SWIFT/Bu...Offlinedoc emotet ext heodo ext ps66uk
2018-08-14 04:31:31http://www.sundayplanning.com/default/US/ACCOUN...Offlinedoc emotet ext heodo ext Cryptolaemus1
2018-08-13 17:41:56http://www.sundayplanning.com/default/US/ACCOUN...Offlinedoc emotet ext heodo ext unixronin
2018-08-09 10:07:07http://www.sundayplanning.com/FLf62Offlineemotet ext exe heodo ext Anonymous
2018-08-07 15:38:06http://www.sundayplanning.com/oHkM/Offlineheodo ext zbetcheckin
2018-08-07 10:05:07http://www.sundayplanning.com/oHkMOfflineemotet ext exe heodo ext unixronin
2018-08-06 14:39:18http://www.sundayplanning.com/files/DE_de/Faktu...Offlinedoc emotet ext heodo ext Anonymous
2018-08-01 16:15:53http://www.sundayplanning.com/files/DE_de/Faktu...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2018-07-24 05:36:46http://www.sundayplanning.com/pdf/US/Client/Inv...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2018-07-21 08:10:40http://www.sundayplanning.com/pdf/US/Client/Inv...Offlinedoc emotet ext heodo ext Anonymous
2018-07-20 03:45:55http://www.sundayplanning.com/08/sites/En_us/DO...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2018-08-25 13:19:24b8be31db3cf8fa74d86929a303a2ae714fb928211f14b777f4a63f2bd1854929doc Heodo
2018-08-25 08:51:50cd2ca0dd480b0e65a97ac35cd701ff8d72fa18e1ac3a212e52659e5eaaf9c175doc Heodo
2018-08-02 17:19:250d24a0249b4a2a3fa40453f2aac7d086219f5d4f6f5a316ab857c4559d79cfb8doc  
2018-08-01 20:36:44ddfa667a6805bf8b9216feb8df15b1590c340914d7142aa142ecb858d117ba9bdocHeodo
2018-08-01 16:35:44e1e6f47f76667d41ff54aa4b94741b5a0faccc5ef1a002694b83a0816ab7722fdoc Heodo
2018-08-01 16:15:53207f084b0cc2eb26c4a7c680a886e3f9bd65f45eed695d504743d6bbaafa9856doc Heodo
2018-07-24 05:36:469eb5ebf4950818df9294072543535ab5bf97a9af906b2c14909a7c79445250cfdoc Heodo
2018-07-22 07:53:009eb5ebf4950818df9294072543535ab5bf97a9af906b2c14909a7c79445250cfdoc Heodo
2018-07-22 06:43:199997faff082088963c088eedcfe40c5490a43a26af763637a376fd7f18e0412fdoc Heodo
2018-07-21 23:18:597411a3de5ed22351f99283b783d220317c83f854e4053e7bdeff393042238186doc Heodo
2018-07-21 20:12:58d2ca69e25ef2e753cc9ca52aa6b9577c0adfe3ff7916b054c6172e4e232ba357doc Heodo
2018-07-21 15:52:508449b8b0faadcfab22485004ccc56e221ddf48083c8569741996115ef56452f2doc Heodo
2018-07-21 09:50:5125dc7d8c8e8880651752382dd3bd8bb32d363bbc5b4d75b8f8ca91105ff4d509doc Heodo
2018-07-21 09:29:028222a199549f259a4b3d2dbb1d1258957c16ff4df0d37eab65a05891de34c091doc Heodo
2018-07-20 03:45:545da441a5129f4d0cb8ab72d45b985fb9238218eee413835e1c6d94686fad9d5ddocHeodo