URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ecologilines.top
Domain registrar:Eranet -
Domain registration date:2022-03-07 22:08:03 UTC
Abuse complaint sent to registrar: Yes (2022-03-08 07:46:01 UTC to info{at}todaynic[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2022-03-08 07:46:02 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-08 07:41:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-08 07:41:04 62.173.149.112khodor.rodion.example.comNot listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-08 07:41:04https://ecologilines.top/notepad.txtOfflineexe geofenced Gozi ext ISFB ext ITA MISE ursnif ext reecdeep
2022-03-08 07:41:04http://ecologilines.top/notepad.txtOfflineexe geofenced Gozi ext ISFB ext ITA MISE ursnif ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-09 07:23:3714e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119eexeGozi
2022-03-09 05:53:531f81af8f4546b7987e0f027d5a169ed2f13c531cb2abdb3bf53d178adf0dca4fexe Gozi
2022-03-09 01:58:590c71e469325880f48ca9ea51a1092a8de66e4076f2123c9ddb1e49c3c6d4d2d2exe Gozi
2022-03-09 00:29:507a09413c1069aa57c3f7fa392524beba2946e52c0e7d19a950f949d7795d3be0exe Gozi
2022-03-08 23:20:24f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eeaexe Gozi
2022-03-08 21:59:56d2996d305d44d4bd2e235e0c7ef48c3bdab626a8852e5d1abccf68e94d233c92exe Gozi
2022-03-08 20:22:08e74e14b36e71787b1be4c18218322ae0b78d643ce5ee7170ed5d3c0b828679d3exe Gozi
2022-03-08 18:50:37b8d2240b48152cdb8a65ca9c147cead454d1f341f308dae3dddc41d2f7adf215exe Gozi
2022-03-08 17:42:106c65c6f3674899f9139ead6125de690cbc88d5b6b782ac736bbc9ed68aebc099exe Gozi
2022-03-08 16:19:08bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0eaexe Gozi
2022-03-08 15:10:5502f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffeexe Gozi
2022-03-08 13:45:5250ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847exe Gozi
2022-03-08 12:29:524bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022exeGozi
2022-03-08 11:17:514cd40ce08b87a5b1cf9ec2c3d9696076f2d7b698609739823786bcc243b89d25exe Gozi
2022-03-08 09:58:26da620c65032d49a148b428dab566fed2a1a9af6fb0f53ffc4ea75ae54a2cd6a9exeGozi
2022-03-08 08:06:4157d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961exeGozi
2022-03-08 07:41:04efd04e8f37b1a511e4c723356220d4c07a27a8e8b5a370ea7a7a6b8a5d98ea6bexeGozi