URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: exeseria.com
Domain registrar:Webnic -
Domain registration date:2023-06-22 08:57:34 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-07-04 12:31:07 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-07-04 12:31:11 91.212.166.30SBL624670AS198953 proton66- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-07-04 13:42:06https://exeseria.com/subordinatiOfflinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:14https://exeseria.com/Offlinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:13https://exeseria.com/apertoOfflinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:12http://exeseria.comOfflinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:12http://exeseria.com/Offlinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:11http://exeseria.com/apertoOfflinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT
2023-07-04 12:31:11https://exeseria.comOfflinebrt geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-07-04 16:58:557d0b3f35f4916e7b988b912715e2e02bc49f6603dfa765a51b8662511868c25adllGozi
2023-07-04 16:55:284d5c45337ef42f8a845b0787cd2b3272efe7286b46ff4f8837edbf4e0aefcd21zip Gozi
2023-07-04 16:14:223533f1769dc26c6ded05790915fd59acdf3a061c4d0a641a8a07622aefc75201dll Gozi
2023-07-04 16:10:08d013a608ecf17c14d9f817d4e48541d93efe95d06e728b4d669483ff1e401c67zip Gozi
2023-07-04 15:34:59cd011ff00865510ae1f4affe3b6815d8405edc9aad2e4d4d4c75125e7d360572zip Gozi
2023-07-04 15:25:26a13d8b06719cfc2130205f430dea5d0436b1b9bb3d03b34cd0ebe7753f30fab7zip  
2023-07-04 14:58:349cd2c8168574eeefc6fa0e1b8a757b6ef82f9142a6e43d86a05168653bb2a32bzip Gozi
2023-07-04 14:51:4830f55eb8b4ecf6949441629e63f3819f8a861982451ee1ffafdd4e497ddfd9cezip Gozi
2023-07-04 14:42:35894668791d06262dd16740235faa3b1672e2cb5cf171954f29abaca421c09265dllGozi
2023-07-04 14:42:10689d9603edc0228d287facf70000f764804e38bc14cacd91603d9d8f9c2adfa9zip Gozi
2023-07-04 13:53:007a9b05ac948cdd3cc8046f1c33e0417d3a88fa91fda249c5a7211dd4fffcbb53dll Gozi
2023-07-04 13:51:595e5bd3e339d7d5773482afcf9f5cd0aa612b5415a250b83f057201aba3a9af2bzip Gozi
2023-07-04 13:49:20894668791d06262dd16740235faa3b1672e2cb5cf171954f29abaca421c09265dllGozi
2023-07-04 13:40:234627ddd3fd354152c5e1b25cd091ffbb951f09d49c39e968bfcf62653012e007zip Gozi
2023-07-04 13:33:533533f1769dc26c6ded05790915fd59acdf3a061c4d0a641a8a07622aefc75201dll Gozi
2023-07-04 13:18:26602a37a53069e45034608e4dd45d8858bd59e0630d33703524d2ee555c659c55zip Gozi
2023-07-04 12:53:44caa5013876275a07a695742e8f0c232b114ac0bd6669c1d8b694024747c1a64azip Gozi
2023-07-04 12:46:37105124be1f12a272d606616e5e6273fd87f8d545223103ca93b1c2e18376c7f5zip  
2023-07-04 12:31:117a9b05ac948cdd3cc8046f1c33e0417d3a88fa91fda249c5a7211dd4fffcbb53dll Gozi
2023-07-04 12:31:102870a81354d09f2c2e7f10a41465526d3391e513014d200b7b80a9fc999819c1zip Gozi