URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: linelectriciti.casa
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Blocked
Firstseen:2021-01-22 06:50:04 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-14 10:04:10 52.16.171.153ec2-52-16-171-153.eu-west-1.compute.amazonaws.comNot listedAS16509 AMAZON-02- IEyes
2025-06-18 06:56:20 34.41.139.193193.139.41.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2025-06-18 06:56:20 34.159.223.4343.223.159.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2025-04-29 23:14:02 34.132.102.66.102.132.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2025-04-29 23:14:02 34.136.111.8181.111.136.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-01-22 06:50:04 62.173.148.91Not listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-22 06:50:04http://linelectriciti.casa/pan0ramic0.jpgOfflinedll geofenced Gozi ext ISFB ext ITA ursnif ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-25 13:34:131687bf406aacd5ceef4f5b9ff8f67885969ad4d19ef73f42d3d23f7c52253305unknown  
2021-01-22 10:20:2563bee368085136ef7eed0823b6d8fb25ffecfd6f6d9050ee26f782e2b35df9a4dllGozi
2021-01-22 09:16:418baffba2ed672607e1535dcbfcc47a264e7b8941f63cf181814d7365e8627d05exeGozi
2021-01-22 07:00:35ca3408df31dc066d6ec4feea0388ca8d0cf5d35393bd5a6f1979b9af590f7615exeGozi