URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ecitynewsattingal.com
Domain registrar:Public Domain Registry -
Domain registration date:2016-01-27 12:15:27 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-09 13:15:08 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-09 13:15:13 202.88.241.29hc9win.asianetweb.comNot listedAS17465 ASIANET- INno
2022-01-27 17:15:11 209.99.40.222209-99-40-222.fwd.datafoundry.comNot listedAS23005 SWITCH-LTD- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-13 19:17:14http://ecitynewsattingal.com/buchi.exeOfflineexe Formbook ext abuse_ch
2021-12-10 10:40:49http://ecitynewsattingal.com/j.exeOfflineexe Formbook ext abuse_ch
2021-12-09 13:15:13http://ecitynewsattingal.com/chief.exeOfflineFormbook ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-13 22:05:32b05301021a46ef289074de0c30a8219e9240bc5a034b718406c9346bd50fe557exeFormbook
2021-12-13 19:17:13592c78e1e6520240a3c32c81aae504ce05a1b66a032ac0056c7fbcac9d3a4150exeFormbook
2021-12-10 10:40:49b13782a081582cd40a427da82c93035d3a59cd7dffea1e9b3f3821c55fde233cexeFormbook
2021-12-09 13:15:116c8818af8ed7a299ff9a86c488fa26b4c8e73bc26d814076bc07d50ff90909c8exe