URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ecologilink.top
Domain registrar:Eranet -
Domain registration date:2022-03-07 22:08:02 UTC
Abuse complaint sent to registrar: Yes (2022-03-08 07:51:02 UTC to info{at}todaynic[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2022-03-08 07:51:02 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-08 07:48:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-08 11:16:19 62.173.148.46Not listedAS34300 SPACENET-AS- RUno
2022-03-08 07:48:07 62.173.154.103Not listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-08 07:48:08https://ecologilink.top/notepad.txtOfflineexe geofenced Gozi ext ISFB ext ITA MISE ursnif ext reecdeep
2022-03-08 07:48:08http://ecologilink.top/notepad.txtOfflineexe geofenced Gozi ext ISFB ext ITA MISE ursnif ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-09 06:13:0314e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119eexeGozi
2022-03-09 05:04:36eda3487d5cce3777e504ae88f362c2352de1642fa86200e005ba5a7a3bfbdec0exe Gozi
2022-03-09 03:28:4054c8911c3fd29d5b1ccf03a983ba0106e0f553db2e72e06251f6fca5a5ad1d81exe Gozi
2022-03-09 02:23:500c71e469325880f48ca9ea51a1092a8de66e4076f2123c9ddb1e49c3c6d4d2d2exe Gozi
2022-03-09 00:58:317a09413c1069aa57c3f7fa392524beba2946e52c0e7d19a950f949d7795d3be0exe Gozi
2022-03-08 23:56:099d78bd7565091ca9bd64766f4d83a4da720ec931bacd8c1d715b56be24cacdb9exe Gozi
2022-03-08 22:31:53f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eeaexe Gozi
2022-03-08 20:59:32d2996d305d44d4bd2e235e0c7ef48c3bdab626a8852e5d1abccf68e94d233c92exe Gozi
2022-03-08 19:19:5305d6ed618ae482d788a0228674163236f32b231f00a8b0d1b23ba0bdc481be60exe Gozi
2022-03-08 17:34:396c65c6f3674899f9139ead6125de690cbc88d5b6b782ac736bbc9ed68aebc099exe Gozi
2022-03-08 16:11:04bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0eaexe Gozi
2022-03-08 15:09:4302f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffeexe Gozi
2022-03-08 13:50:2850ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847exe Gozi
2022-03-08 12:28:334bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022exeGozi
2022-03-08 11:16:164cd40ce08b87a5b1cf9ec2c3d9696076f2d7b698609739823786bcc243b89d25exe Gozi
2022-03-08 09:48:309eb0bdb45d505a24290b3fe9adb1ac5c856238e91358fcf7e6af73d9a1b9c244exeGozi
2022-03-08 08:14:3857d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961exeGozi
2022-03-08 07:48:07efd04e8f37b1a511e4c723356220d4c07a27a8e8b5a370ea7a7a6b8a5d98ea6bexeGozi