URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: danielmi.ac.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-07-23 12:07:03 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-07-23 12:07:10http://danielmi.ac.ug/ds2.exeOfflineexe RedLineStealer ext abuse_ch
2021-07-23 12:07:09http://danielmi.ac.ug/rc.exeOfflinebitrat ext exe RemcosRAT ext abuse_ch
2021-07-23 12:07:06http://danielmi.ac.ug/cc.exeOfflineexe Smoke Loader ext abuse_ch
2021-07-23 12:07:06http://danielmi.ac.ug/ac.exeOfflineAsyncRAT ext exe abuse_ch
2021-07-23 12:07:05http://danielmi.ac.ug/ds1.exeOfflineexe RedLineStealer ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-16 12:23:16d4c6f300ccf9337a10d13a66a2b6b956a0e6e9673741f9b88f5811beb3a62829exeRemcosRAT
2021-08-16 11:40:30081d4cc20e46574bc49b49558940371ce6b0a037d61ee2915e3a16f588de4eb8exeAsyncRAT
2021-08-16 11:39:1744e3a5d07ad41e0c1e023eeb97798f0822d706abb3406b61466d32a7d29c8726exeSmoke Loader
2021-08-08 11:55:20ce294b3c9e58d2d6394e2aa447ad3b586e0e23cdd22bd050a362bdd57a3e3fe9exe 
2021-08-08 11:53:15d40371030031fc84f0cd14b20865ab1a243b4fb45c1afb4075067a97591bcceeexeRemcosRAT
2021-08-05 09:36:57eeed35b6db912ba4accd50f23c4abd5f517cf9bb2981e1286c1783424121be14exeSmoke Loader
2021-08-05 09:35:500088daad429de39bd42663b9b508af98da7b8a3d09e4b7ff0012a8901a32253bexeBitRAT
2021-08-05 09:32:02fa98235aae1687afb628d39a16645b6d2f4afeb97d113229c660425464e296c2exeRedLineStealer
2021-08-05 09:23:29c58ec23d6e9d1f548d0d9375009bf23ebfb9f40eb9bb14fccc4e10f385f53d5dexeRedLineStealer
2021-08-05 09:18:502d5d1a4d6bc5abb1e0ad26c3d9801a44317d0a50a370db5de488763b98fc766bexeAsyncRAT
2021-07-23 12:07:10871c62959e739a3796291f18a156d73f6cb16092f86e4e33a28dec191977e8aeexeRedLineStealer
2021-07-23 12:07:091d2ad0e9b26a1e83ea43e5c17658df821c78bf4044aa0c6d71d01452584a67b4exeBitRAT
2021-07-23 12:07:06fad40e1841789cfbef3c9f09b4e557b928597506cd8b93d8eae51cef2ba3cf3fexe 
2021-07-23 12:07:06d49479f1e5b04736f8bab7ff79f8cd3574234fa244b1f414b74b1fd91f87d1fbexeAsyncRAT
2021-07-23 12:07:0540cd463ec941b66e1f65ea9e1e9ca7ab0c0211ebc38ea7250eaa3a9012c61cf9exeRedLineStealer