URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ddlakava.ac.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-09-06 08:09:02 UTC
Total malware sites :1
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-05-27 10:52:30 94.142.138.213SBL655622AS211522 HYPERCORELTD- FIno
2023-05-03 16:17:54 91.215.85.135SBL615768AS200593 PROSPERO-AS- RUno
2023-04-14 15:56:54 94.142.138.104SBL655622AS211522 HYPERCORELTD- FIno
2023-03-16 16:28:52 91.215.85.173SBL615768AS200593 PROSPERO-AS- RUno
2022-12-18 13:00:28 91.215.85.158SBL615768AS200593 PROSPERO-AS- RUno
2022-08-11 00:12:20 45.143.201.4free.ntup.netSBL625748AS200195 VERASEL- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-09-06 08:09:15http://ddlakava.ac.ug/ghjkl.exeOffline32 ArkeiStealer ext AZORult ext CoinMiner exe RaccoonStealer ext RecordBreaker ext Rhadamanthys Vidar ext zgRAT zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-08-07 14:34:4929f5a8629986da0b4a353e5423fb39c505cba7c06e7aa4b5a4029c5a1669ae95exeRhadamanthys
2023-07-25 00:35:55dbe40b9e6a1cdb3db55a42228312ec4b8e5661ccef00dee81daadbe5bc56490eexe 
2023-07-19 13:04:11bcf3266e8996bcdb7acb686034f264b07c228ce37f1212b663b636cc0317ee1aexe AZORult
2023-06-25 03:26:11fc6ddb1f7644597b84d14e3efa4cd1a1d1ad0083141b3fa2a613cd3c092f6505exeRhadamanthys
2023-06-22 03:38:517c53ab4cf5f997aa947c4fbadeccbbb7b43eb0eb204f57b446d87ae442d84eeaexe 
2023-06-21 22:14:229c5f8a135e8ccfb39dc834cd68e0a03e55748996afc05d79a20797ea3139093bexe 
2023-06-21 05:23:5240dced6790e58f1270085a263a71587925a23b113557a16e0bff530baf6d1810exe 
2023-06-20 18:51:3007632404faa7fd83a0f1e4e9da20173c3f9ca38affd286a90dc362c73b26ee8eexe  
2023-06-12 01:13:445329037805cd075c557cd93ec733e06f9b70c1a8492135d4647c6820f1a3231bexe  
2023-05-28 13:33:275d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979exe AZORult
2023-05-12 05:33:50bf1d731a91e424fd67778f176ac652fa5ca39f2ab188ef740184e4b2808c7b3cexeAZORult
2023-05-11 13:47:4579a7c9d15971c14d78baccbf211b3ca1e9adcb0befc6d3d1c5d92902d70678e2exeAZORult
2023-05-08 18:16:5584c18f78f11b9bc3fd3e96925d2a7b76ab5ecfb927c377ad27456e191815b24aexeCoinMiner
2023-05-08 17:51:36c8dcace2c920912998c27f396e8945fa924757f3a7596a2da6044c1d0d47c7abexe 
2023-05-03 11:13:3583263fa7b8c560ae026a24d6ea9e6eafb16aa207cc5557c65c7f71f703f3a593exe  
2023-05-01 15:26:38e99f79618b991de5d1052096950590a4fe833b885871a96bb1202e3d6dd876a0exe  
2023-04-30 11:50:33ff277e11345c79a60de0ba45011460629487e82e8b0b58a8ddfdfeca2d7623f5exe  
2023-04-22 15:10:000127ebf8628f963a453520b0149fc11fc5d0a56536ce2a41c9dfdd3c597a0746exe zgRAT
2023-04-18 10:26:16d9b498faf01b9eb598761915a6fc2fb4f1ab2317d354348baca6794730fd15d3exeVidar
2023-04-14 17:24:540cff8404e73906f3a4932e145bf57fae7a0e66a7d7952416161a5d9bb9752fd8exe Vidar
2023-04-08 22:44:395119433510a4aee04ba7f2ead9f3e636081f2571a6eb39997d49aca021a0a28bexe 
2023-04-07 16:26:364130ce135fbfab00618f261a0397e88479d2f61e1ed0d09ebcde525439774f3eexe AZORult
2023-03-23 11:06:1660289bfd6a3a67726074cccced70f113419fea3b76c00855fb7dc5fa332d3f7aexeRhadamanthys
2023-03-16 16:28:52a54493e71a7f28fe61e607ba4c089ada71e13ff9e1df6cef5619a4163e2b0a1fexeAZORult
2023-02-05 09:08:584908e51e65bf67fdc3a559be7c47c3df1354a4a864b931cb176d282048f8d9c2exeAZORult
2023-01-13 06:09:118c5df030de0c79f2155a60e0d5f41889ec8d07d441279d406996dca4639f8539exeRecordBreaker
2022-12-18 14:24:05746669c6be1807fdafbc7ee3f1e958e1b584fa31688742bcc044d269af94b0d8exeRecordBreaker
2022-11-26 16:22:399063dd7d69236cca3007587ccc04334b4289ec456f6983673f3d9f749092a29cexeRecordBreaker
2022-10-06 00:43:07d4227ec9dd2159223342099e0ed7d55c0691fe677ab2fc513c149a137e50ced8exeAZORult
2022-10-02 10:54:29f0c0ac751d55d69d9e82c66e7f7f8ab5e298c5808302e8b6424ad3aa1bf1c338exe  
2022-10-01 16:27:439a81a9c84d36a49be8286458ce7c919538647711b28fedae9b5521762ff76030exe  
2022-09-16 10:28:24e553b05dd2afafadb6ad38d3463056e50cfa31ba3ac5489a7a114ec35ef10194exeRecordBreaker
2022-08-19 04:59:4865020d58d04109f2e8f46d12e43aeee9e98ec182db4bd4a2b2c336978e696c06exeAZORult
2022-08-14 05:18:20ea34b776b896df9512f0aab37e3b0d56ff012a0906910a957db335f9e7dcf2d4exe RecordBreaker
2022-08-11 00:12:20d75d7b0534ff648f16f5751be79a2c23158b6412a780180aec78c77c7e95071dexeAZORult
2021-10-03 08:20:39394c61c695af669dcfe4d3dcf73de5099ed8e7fea036dd25f45ff6d234f9547aexeArkeiStealer
2021-09-27 21:25:344b4392d46103cc0a5116c62cd042d7817a4b749949cc5d45610b57d23cb47527exe 
2021-09-25 06:23:243ef65642968377f832f577a3631fac424e24e3c86ead5539d31b0583ddd69de3exe RaccoonStealer
2021-09-17 13:01:06e80d7de90473de5e1d9fb140d2537896872f7a7ca665e9342514426604f4f708exeRaccoonStealer
2021-09-11 14:04:357b8ffb495d71939d9dfb9b4f4b0bd9bd9d3fad675aa487e2b20129c33f877c50exeArkeiStealer
2021-09-06 08:09:1593ddf61c1aa7c0b867ffbd579b9febdeed4b027d14f8b86d62f7da493706731cexeAZORult