URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gosuclugi.co
Domain registrar: n/a
Domain registration date:2021-12-12 15:00:26 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-14 04:36:04 UTC
Total malware sites :1
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-16 10:55:57 34.227.188.100ec2-34-227-188-100.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-03-14 13:11:41 54.204.23.37ec2-54-204-23-37.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-02-15 01:43:40 35.175.1.129ec2-35-175-1-129.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-02-19 18:02:46 72.44.41.228ec2-72-44-41-228.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2022-02-17 08:55:33 3.210.218.108ec2-3-210-218-108.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-02-17 08:55:33 34.198.87.3ec2-34-198-87-3.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2022-02-15 01:43:40 35.171.15.242ec2-35-171-15-242.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2022-01-14 04:36:16 185.193.66.100vmi1034210.contaboserver.netNot listedAS51167 CONTABO- FRno
2022-03-13 23:51:58 3.208.177.33ec2-3-208-177-33.compute-1.amazonaws.comNot listedAS14618 AMAZON-AES- USno
2022-03-14 13:11:41 3.223.132.123ec2-3-223-132-123.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-14 04:36:16http://gosuclugi.co/upl/b91df3382fb792927b7a43f...Offline32 ArkeiStealer ext exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-14 04:36:1548c7a0f90aeb87e9ba5feb08b5bedbcb70aacf2632636f71a62e2ffdd551ec98exeArkeiStealer