URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: lo.seculogo.sa.com
Domain registrar:Sav.com -
Domain registration date:1998-06-25 04:00:00 UTC
Spamhaus DBL :Spammer domain
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-05-24 23:01:06 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-29 18:08:56 34.76.205.124124.205.76.34.bc.googleusercontent.comSBL656841AS396982 GOOGLE-CLOUD-PLATFORM- BEno
2025-05-24 23:01:12 172.93.120.11myhijab.worldNot listedAS393960 HOST4GEEKS-LLC- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-05-27 07:04:33https://lo.seculogo.sa.com/docs/jqbjyhic.JSOfflineascii js opendir abuse_ch
2025-05-27 07:04:10https://lo.seculogo.sa.com/docs/lyxcwjcsd.txtOfflineascii opendir RemcosRAT ext rev-base64-loader abuse_ch
2025-05-27 07:04:10https://lo.seculogo.sa.com/docs/trximbxru.txtOfflineascii opendir RemcosRAT ext rev-base64-loader abuse_ch
2025-05-27 07:04:09https://lo.seculogo.sa.com/delivered/Eijhmtanpy...Offlineexe opendir abuse_ch
2025-05-27 07:04:07https://lo.seculogo.sa.com/docs/weomodeog.txtOfflineascii Formbook ext opendir rev-base64-loader abuse_ch
2025-05-27 07:04:04https://lo.seculogo.sa.com/docs/x1.JSOfflineascii js opendir abuse_ch
2025-05-27 07:04:04https://lo.seculogo.sa.com/docs/zvgxsaea.JSOfflineascii js opendir abuse_ch
2025-05-27 07:03:06https://lo.seculogo.sa.com/orders/lcviygujm.txtOfflineascii Encoded Formbook ext opendir rev-base64-loader abuse_ch
2025-05-27 07:03:06https://lo.seculogo.sa.com/docs/Wire_Transfer_C...Offlineopendir zip abuse_ch
2025-05-27 07:03:05https://lo.seculogo.sa.com/orders/WireTransferC...Offlineopendir zip abuse_ch
2025-05-27 07:03:05https://lo.seculogo.sa.com/orders/PO010016218AN...Offlineopendir zip abuse_ch
2025-05-27 07:03:04https://lo.seculogo.sa.com/orders/veueobbh.JSOfflineascii js opendir abuse_ch
2025-05-27 07:02:10https://lo.seculogo.sa.com/orders/Chddewmrihyrd...Offlineexe Formbook ext opendir abuse_ch
2025-05-27 07:02:09https://lo.seculogo.sa.com/share/mgaihkwag.txtOfflineascii Encoded Formbook ext opendir rev-base64-loader abuse_ch
2025-05-27 07:02:08https://lo.seculogo.sa.com/share/tqrkolhnd.txtOfflineascii Encoded Formbook ext opendir rev-base64-loader abuse_ch
2025-05-27 07:02:07https://lo.seculogo.sa.com/share/dczdeukri.txtOfflineascii Encoded Formbook ext opendir rev-base64-loader abuse_ch
2025-05-24 23:01:14http://lo.seculogo.sa.com/docs/weomodeog.txtOfflineFormbook ext rev-base64-loader DaveLikesMalwre
2025-05-24 23:01:13http://lo.seculogo.sa.com/share/mgaihkwag.txtOfflineFormbook ext rev-base64-loader DaveLikesMalwre
2025-05-24 23:01:12http://lo.seculogo.sa.com/share/tqrkolhnd.txtOfflineFormbook ext rev-base64-loader DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-27 07:04:100ae2f238bd831633cc9a971550ec68508018d9fa403872dbba00d7b0289035b7txt RemcosRAT
2025-05-27 07:04:1046d98610e2af32aa0670d7ba148b467562fb54a598b8f590b967fb2e4945f01dtxt RemcosRAT
2025-05-27 07:04:09e9eb5b546421b5932b0c44815a6273d7496c066f882830a071923a330a00fb39exe  
2025-05-27 07:04:07fce2c41d1bd1d1afc048bdda845200ddf7748a9ea70bcd03ba3441c1561cd593txt Formbook
2025-05-27 07:03:0695bc6edb486629c365cc0d92a6ca287f28f5bce56a29867224f6d7ce6b7dc76fzip  
2025-05-27 07:03:06fce2c41d1bd1d1afc048bdda845200ddf7748a9ea70bcd03ba3441c1561cd593txt Formbook
2025-05-27 07:03:055b2de8cbeb29395a519c91083066e152011c7f20f585129b9f3903e6cf57bb23zip  
2025-05-27 07:03:05fcda1bc34721674d35666d318de37b74d70154adc869b37a04acb5b7cd94a8cezip  
2025-05-27 07:02:10c39519f320198ad39fb3f6c1990594c6144484e7c86cb4b326c4e92ad65bc4cfexe Formbook
2025-05-27 07:02:0938c7e40a31288c58380f68166d7c076ab2ef9cbba27bbc0d614ad9946289d636txt Formbook
2025-05-27 07:02:07fce2c41d1bd1d1afc048bdda845200ddf7748a9ea70bcd03ba3441c1561cd593txt Formbook
2025-05-27 07:02:0738c7e40a31288c58380f68166d7c076ab2ef9cbba27bbc0d614ad9946289d636txt Formbook
2025-05-24 23:01:14fce2c41d1bd1d1afc048bdda845200ddf7748a9ea70bcd03ba3441c1561cd593txt Formbook
2025-05-24 23:01:1338c7e40a31288c58380f68166d7c076ab2ef9cbba27bbc0d614ad9946289d636txt Formbook
2025-05-24 23:01:1238c7e40a31288c58380f68166d7c076ab2ef9cbba27bbc0d614ad9946289d636txt Formbook