URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: geo-foundation.vg
Domain registrar:NICENIC -
Domain registration date:2026-03-11 11:50:34 UTC
Abuse complaint sent to registrar: Yes (2026-03-14 16:18:01 UTC to support{at}nicenic[dot]net)
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-03-14 16:11:05 UTC
Total malware sites :2
Online malware sites :1 (50%)
Offline Malware sites :1 (50%)
Newest active malware site :2026-03-14 16:11:14 UTC
Oldest active malware site :2026-03-14 16:11:14 UTC (Age: 4 days, 15 hours, 15 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-14 16:11:14 31.56.176.201Not listedAS56971 AS56971- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-14 16:13:05https://geo-foundation.vg/police.pdfOfflineascii powershell ps1 abuse_ch
2026-03-14 16:11:14https://geo-foundation.vg/Onlineascii CountLoader ua-mshta abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-19 03:00:30c423b5364c81a476aacb0b9cb75c90b2f7762ac8578f344c8e45f3c8b4e3476cjs  
2026-03-18 20:35:46e712aaf403d47df55bc87d0e298efe256902990a9c1f225ca5e36a061eade395js  
2026-03-18 14:57:16f09c11ada12b8bfabf76c9c48ee8cf15a4a7af848fbc99ecfbbf351764eb9373js  
2026-03-18 08:54:455790c9545a9e42588063c2f309dc710957efdda8ba05858f7b33d23101763ac1hta 
2026-03-18 08:37:57c511fc7f9049646a189c0989e1b355fb29adf4fd476e284e47f04d660a60c324hta 
2026-03-18 07:51:21964676e342c14571397111d8916f3fc8e810c9fa0234c5e27b9dfa02f43aeb8bhtaCountLoader
2026-03-18 03:34:0593eb1e8c168b57103e3511b3b3700f28a5e2b3ff62208cf84c3d5f49f86b7865hta  
2026-03-17 20:21:26691a6e46a7c0e2f2a0a5ae4e7d5c64deb03e230d0202cb4bed82e27188c485d2htaCountLoader
2026-03-17 17:35:469f12096d9dac3217a38d6e93d207e2b4afaa6f08437d56547befeb517f83feaahtaCountLoader
2026-03-17 15:14:175f585180c375d3aceb3c6e9f51d8dc2ddeedd0647c5603ca1b4f93265bea0ffehtaCountLoader
2026-03-16 21:29:47eaf30f74d02afd9c49791d101edec792d84db4c3623b14ab68cee84c9db07f8chtaCountLoader
2026-03-16 14:31:52bb7141c427671b8df3e3678c2427d1f7547d668a324bcdb5f04607f6cb02c44ehtaCountLoader
2026-03-16 09:11:391cc3b919978866d0a2f4d0f504914e8fd6e50bec4acea4c298ee554d51a04a74htaCountLoader
2026-03-16 06:11:020a9eef7efa92b0d9d10aaf03061969c932867848ceceb380624847a20a41d22bhtaCountLoader
2026-03-16 03:28:29c9ea5f5273e8d4855c6f32fe105a4583b360e055b9ef333ed5fe9a50247d4874htaCountLoader
2026-03-15 20:42:30ce96aca71f071a1c4f688b4503ebe04b53fc75bc91252e0aded2255b4a1b13aehtaCountLoader
2026-03-15 14:15:296caefde626311178946e86ebb0df91359834b3c993a8920eff5a35307421ad92htaCountLoader
2026-03-15 09:21:362c98a7452c49ccd942303624fc9bc279711a8bba0d0a65675a3b103d9ab157f8htaCountLoader
2026-03-15 06:51:43cbbd13986ddd2c3703e666e027a0c7dfb310d54299a6527212e836393e1bcd07htaCountLoader
2026-03-15 02:42:566af3457051330059b04eea8a42d1ed8f08bf92a29ea981cd5e94b71c2f25c493htaCountLoader
2026-03-14 20:22:268f8e3dbbdab719fad3f6748bde5301b9b3e35aea0ba58407a8e785bcfc6e9f14htaCountLoader
2026-03-14 20:04:586370b0bf653168199cd75957cc1cb02a9f50871882c87a31ba091de6ba4a0d49htaCountLoader
2026-03-14 16:11:1436cd729674787b8d7fc0830779afc98eb5958c3e07d4cbad0d0dee5c50f70a56htaCountLoader