URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gdx.o7lab.me
Domain registrar:Atak Domain -
Domain registration date:2023-06-21 08:00:26 UTC
Spamhaus DBL :Malware domain
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-08-04 17:08:04 UTC
Total malware sites :15
Online malware sites :0 (0%)
Offline Malware sites :15 (100%)
A record(s) observed :13

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-01-20 00:20:32 85.31.47.56Not listedAS397423 TIER-NET- BGno
2024-12-27 10:07:44 94.156.167.42Not listedAS208220 offerhostinc- BGno
2024-11-26 09:44:09 85.31.47.143Not listedAS397423 TIER-NET- BGno
2024-11-04 10:47:44 31.13.224.130Not listedAS151612 HOSTPERL-AS-AP- NZno
2024-10-29 11:08:02 45.149.241.238Not listedAS57653 CTL-AS- GBno
2024-10-26 09:35:29 93.123.109.4893-123-109-48.sarnica.netSBL677469AS48090 DMZHOST- BGno
2024-10-12 10:32:47 194.48.251.46Not listedAS205533 AMEETECHLTD- BGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-11-01 03:48:10http://gdx.o7lab.me/svcsvr.exeOffline32 exe QuasarRAT ext zbetcheckin
2024-10-30 04:18:05http://gdx.o7lab.me/winsvc.exeOffline32 exe RedLineStealer ext zbetcheckin
2024-10-29 15:36:30http://gdx.o7lab.me/plugin2.dllOffline abus3reports
2024-10-29 15:36:13http://gdx.o7lab.me/.exeOfflineRedLine ext RedLineStealer ext abus3reports
2024-10-29 15:36:09http://gdx.o7lab.me/plugin1.dllOffline abus3reports
2024-10-29 15:36:09http://gdx.o7lab.me/plugin3.dllOfflineCoinMiner encrypted PureCrypter PureMiner xmrig abus3reports
2024-08-04 17:10:10http://gdx.o7lab.me/dns.exeOfflineAsyncRAT ext exe abus3reports
2024-08-04 17:10:10http://gdx.o7lab.me/svchost.exeOfflineAsyncRAT ext exe QuasarRAT ext abus3reports
2024-08-04 17:10:08http://gdx.o7lab.me/ip.exeOfflineexe VenomRAT abus3reports
2024-08-04 17:10:07http://gdx.o7lab.me/taskhostw.exeOfflineexe VenomRAT abus3reports
2024-08-04 17:10:06http://gdx.o7lab.me/task.exeOfflineexe VenomRAT abus3reports
2024-08-04 17:10:06http://gdx.o7lab.me/client.exeOfflineexe VenomRAT abus3reports
2024-08-04 17:08:18http://gdx.o7lab.me/2.exeOfflineAsyncRAT ext exe abus3reports
2024-08-04 17:08:11http://gdx.o7lab.me/3.exeOfflineexe VenomRAT abus3reports
2024-08-04 17:08:11http://gdx.o7lab.me/1.exeOfflineCoinMiner exe VenomRAT abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-17 12:57:529085f21c1b1530bba6a058781ff7ebf33928dbecfe39ffb7bd2fc34344ac6bdbexeCoinMiner
2024-11-04 22:17:1512768a43e1b2756090d4b45961aed9ffabc64d8df0dc1a88ccc73b9393f1f16aexe  
2024-11-01 03:48:1082687bbf89460d44b3cef2d06f5d09288c45d787323254026f39cb3421cc3954exeQuasarRAT
2024-10-30 04:18:05d3d22f35f4571d498c8d6cb177cc260301652b9dd030ca431bd6bf2a4626f0c4exeRedLineStealer
2024-10-29 15:36:302f0103a5d98ec1c576418a9b8db855e4bc1ed02b5938483a42cf8e2b1ec6cf8funknown  
2024-10-29 15:36:13a034366648b01d614c154f3cbf371916be93bcd3f7a02a2b36209af355beaf79exeRedLineStealer
2024-10-29 15:36:092701485e85807789307bc411d385445ceb0fc902f82a510cd0db46eb36308152unknown  
2024-10-29 15:36:090041032b7f7ba0265c09bdb0958f635ae852bbd86164ad0ab6944be760013491unknown  
2024-10-17 17:05:3028e5a0c9c2af3c2c622104f74f3f042aaf689f85cf025dc7e8db28ae1204cf18exe QuasarRAT
2024-10-17 12:32:51155c196ac40326202d2cbe25587894b6e7483696c47787ac95beb30f19ccf814exe AsyncRAT
2024-10-17 04:29:23f48f8fc6adab967e8b5c46ae35296ca524e7e4c3437b5be607f12a1b37d4fd43exe  
2024-08-04 17:10:107ce2d225442252064d744be1c38e9c1572dd355bbbaf7fa411ce79e41288dfcaexeAsyncRAT
2024-08-04 17:10:102a5dac302572ede5da5d53df170d5882937027b58290b6ea60e24478453276c9exeAsyncRAT
2024-08-04 17:10:073b03a24bfde864b0d8b17213f7f2deb6d7e3f5f74b34d3b601cbadd961b904fcexeVenomRAT
2024-08-04 17:10:07408c4cb78449baf846592637c9a8f03f47c3df6786acdce6e9ad0ef0db370068exeVenomRAT
2024-08-04 17:10:061ef225d55b567e06ca8c6197aa237b76504a1a270a512b80b50280154af98146exeVenomRAT
2024-08-04 17:10:066475637fff05177a05bf6e84301c09492f21766ea3ba0068f3f70c4d0d886a9eexeVenomRAT
2024-08-04 17:08:17d61022cef95af3e20bb237b2690c817d948c3ea99a5f11153eca3bcfff034eb0exeAsyncRAT
2024-08-04 17:08:11749911c61e23b64b45f28d453a8b70275f824092d8dab39ccc1e93464d26b450exeVenomRAT
2024-08-04 17:08:11df9d5a6d4edf1baf28fe59cc742cb980dfba7613a17b50c5a75f3fdd756bbc54exeVenomRAT