URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: codeassociates.co.ke
Domain registrar: n/a
Domain registration date:2022-02-03 11:01:54 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-05-03 19:45:10 UTC
Total malware sites :1
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 08:46:51 102.218.215.150da12.host-ww.netNot listedAS329184 Host-Africa-AS2- ZAyes
2023-07-07 07:21:12 148.113.166.117ns5025119.ip-148-113-166.netNot listedAS16276 OVH- CAno
2023-06-18 22:45:50 139.99.8.137ns536018.ip-139-99-8.netNot listedAS16276 OVH- SGno
2023-06-10 17:46:31 67.225.192.149seventeen.deepafrica.comNot listedAS32244 LIQUIDWEB- USno
2023-05-03 19:45:13 69.16.238.78twenty.geonta.comNot listedAS32244 LIQUIDWEB- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-05-03 19:45:13http://codeassociates.co.ke/gnome2/rentfree.zipOfflinegeofenced obama260 Qakbot ext qbot ext Quakbot ext USA wsf zip Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-23 10:01:16e480c5556efd90bf1c71eb9a645ad1c7c31b2610f68aec7ac57a28218446484chtml 
2025-11-21 17:50:49694608d38b05b9e2af7f3140545498baede355f91ee5a877928bec4009dce805html 
2023-05-03 19:45:133b4ff1aaef3aa9125b18d001843ccf04fa970c31d8aafbfadfd4c2966cc4fe00zip Quakbot