URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gofile.io
Domain registrar:OVH -
Domain registration date:2014-11-26 20:30:25 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-04-08 06:16:04 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-24 11:20:06 45.112.123.126Not listedAS214390 GOFILE- FRyes
2025-11-28 17:38:16 51.159.107.11947ee421b-49ae-49c3-aebb-33a95c42805d.fr-par-2.baremetal.scw.cloudNot listedAS12876 AS12876- FRyes
2025-07-09 00:48:14 51.75.242.210mail.gofile.ioNot listedAS16276 OVH- FRyes
2022-04-08 06:16:05 151.80.29.83ns3048708.ip-151-80-29.euNot listedAS16276 OVH- FRno
2022-04-08 06:16:05 51.178.66.33ns31226493.ip-51-178-66.euNot listedAS16276 OVH- FRno
2022-04-08 06:16:06 51.38.43.18ns3120834.ip-51-38-43.euNot listedAS16276 OVH- FRno
2026-04-17 00:27:22 160.202.167.55Not listedAS137409 GSLNETWORKS-AS-AP- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-26 07:13:05https://gofile.io/d/c29fee76-0347-4c35-a814-c59...Offlinebotnet exe Gofile LasseƱosattack Anonymous
2025-10-19 06:40:05https://gofile.io/d/upBS3NOfflineAsyncRAT ext asyncthecatgirl
2025-07-03 16:25:06https://gofile.io/d/l8d8IwOfflineAsyncRAT ext exe Anonymous
2025-07-01 14:45:08https://gofile.io/d/bd2738ff-d42d-413a-9de9-4cf...OfflineCredentialStealer zip abuse_ch
2025-06-12 22:53:03https://gofile.io/d/YuiCmSOfflineexe Riordz
2025-06-11 20:40:06https://gofile.io/d/OsO6lsOfflineexe emmathecatlol
2025-06-11 20:39:06https://gofile.io/d/l6sYAcOfflineexe emmathecatlol
2025-06-11 20:39:06https://gofile.io/d/p17S0WOfflineexe emmathecatlol
2025-06-11 20:39:06https://gofile.io/d/PZj9UrOfflineexe emmathecatlol
2025-06-11 20:39:05https://gofile.io/d/8Lj3w2Offlineexe emmathecatlol
2025-06-11 20:39:03https://gofile.io/d/A1sfYFOfflineexe emmathecatlol
2025-04-24 11:20:06https://gofile.io/d/1sr5IIOffline iLikeMalware
2025-04-24 11:20:06https://gofile.io/d/HD2Q1eOffline iLikeMalware
2025-04-24 11:20:06https://gofile.io/d/otob44Offline iLikeMalware
2025-04-24 11:20:06https://gofile.io/d/O6YXVUOfflineexe rat iLikeMalware
2024-04-23 15:50:07https://gofile.io/d/EmP0zoOfflineDacic abus3reports
2024-03-29 00:01:09https://gofile.io/d/Fk8QQDOfflinedropped-by-SmokeLoader spamhaus
2024-03-29 00:01:08https://gofile.io/d/0ZZVr7Offlinedropped-by-SmokeLoader spamhaus
2022-04-08 06:16:06https://gofile.io/d/NP7KFcOfflineexe Myrtus0x0

The table below shows recent payloads delivery by this host.