URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: malayska.ug
Abuse complaint sent?: Yes (2024-06-28 05:25:03 UTC to cmusisi{at}uol[dot]co[dot]ug,ksemat{at}eahd[dot]or[dot]ug)
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-04-11 10:01:03 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-17 19:28:28 34.41.139.193193.139.41.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USyes
2025-06-17 19:28:28 34.159.223.4343.223.159.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2025-04-27 11:09:32 34.132.102.66.102.132.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2025-04-27 11:09:32 34.136.111.8181.111.136.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2024-06-28 05:24:06 91.215.85.223SBL615768AS200593 PROSPERO-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-06 05:42:24http://malayska.ug/telly.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:42:13http://malayska.ug/qwertyj1.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:39:19http://malayska.ug/mkv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:38:45http://malayska.ug/zxcv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:38:44http://malayska.ug/asdf.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:38:21http://malayska.ug/ppx.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:36:40http://malayska.ug/ali.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:27:37http://malayska.ug/qwerty.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:21:12http://malayska.ug/zxcvb.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:14:26http://malayska.ug/zxcvb.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:14:13http://malayska.ug/payload.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:13:39http://malayska.ug/pps.ps1Offlineopendir ps1 NDA0E
2024-06-28 05:24:06http://malayska.ug/asdfg.exeOffline32 exe Rhadamanthys zbetcheckin
2024-06-28 05:24:06http://malayska.ug/net.exeOffline32 exe Rhadamanthys zbetcheckin
2024-06-28 05:24:06http://malayska.ug/ghjkl.exeOffline32 exe Rhadamanthys zbetcheckin
2024-06-28 05:24:06http://malayska.ug/native.exeOffline32 exe Rhadamanthys zbetcheckin
2024-06-28 05:24:06http://malayska.ug/asdf.EXEOffline32 exe Rhadamanthys zbetcheckin
2022-04-11 10:01:06http://malayska.ug/ghjk.exeOfflineAZORult ext exe RedLineStealer ext vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-08 13:57:0133682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 11:05:4733682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:24:3933682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:45:1233682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:36:5333682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:32:3433682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-06 05:21:117ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-04 21:28:087ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-04 19:48:187ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-04 16:59:537ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-04 16:52:077ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-04 15:19:137ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-06-29 11:03:031be72df03d119533254240c7553b6fc6af0b28c58182ac937684ea0fe8a41b4eexe  
2024-06-29 10:01:28f567eb23dd95fe66f925bce074253f46263b0916de62d8850dd8c3ac35efc72eexe  
2024-06-29 00:45:20f567eb23dd95fe66f925bce074253f46263b0916de62d8850dd8c3ac35efc72eexe  
2024-06-28 22:04:25a2e4f1eead7d430cf08d33e04c48adb2af23b71ec4c633bc6b88d870c1d61a56exe  
2024-06-28 21:16:274a69a64d652063b65cfe7f7ad5e54491b06547c783d74147c79cb9145536cf26exe 
2024-06-28 20:35:148491781afed15ad4fa80b176c3516cd3b44e7880a559ab22899b216be74cec48exe  
2024-06-28 19:20:138491781afed15ad4fa80b176c3516cd3b44e7880a559ab22899b216be74cec48exe  
2024-06-28 18:42:458491781afed15ad4fa80b176c3516cd3b44e7880a559ab22899b216be74cec48exe  
2024-06-28 17:58:4224f6c1b06912c2d8d46c6ac10737fd8efaaf7d18b227279f9dae584a5625c0c6exe  
2024-06-28 17:48:55f567eb23dd95fe66f925bce074253f46263b0916de62d8850dd8c3ac35efc72eexe  
2024-06-28 17:13:3624f6c1b06912c2d8d46c6ac10737fd8efaaf7d18b227279f9dae584a5625c0c6exe  
2024-06-28 15:48:12a2e4f1eead7d430cf08d33e04c48adb2af23b71ec4c633bc6b88d870c1d61a56exe  
2024-06-28 15:21:2224f6c1b06912c2d8d46c6ac10737fd8efaaf7d18b227279f9dae584a5625c0c6exe  
2024-06-28 15:03:29f567eb23dd95fe66f925bce074253f46263b0916de62d8850dd8c3ac35efc72eexe  
2024-06-28 14:15:35a2e4f1eead7d430cf08d33e04c48adb2af23b71ec4c633bc6b88d870c1d61a56exe  
2024-06-28 14:12:17f567eb23dd95fe66f925bce074253f46263b0916de62d8850dd8c3ac35efc72eexe  
2024-06-28 13:49:3424f6c1b06912c2d8d46c6ac10737fd8efaaf7d18b227279f9dae584a5625c0c6exe  
2024-06-28 09:08:248c13fdcfeb87abd390f487e9d51d7edcdd6073951a5f96e5c0b1f7d899874932exe 
2024-06-28 08:46:108c13fdcfeb87abd390f487e9d51d7edcdd6073951a5f96e5c0b1f7d899874932exe 
2024-06-28 08:38:2247a817f85453e16e52d201810fd5a719a1fcb01c49dfd350a2fc36fef42ac442exe 
2024-06-28 07:48:3247a817f85453e16e52d201810fd5a719a1fcb01c49dfd350a2fc36fef42ac442exe 
2024-06-28 06:42:088c13fdcfeb87abd390f487e9d51d7edcdd6073951a5f96e5c0b1f7d899874932exe 
2024-06-28 06:34:43a2e4f1eead7d430cf08d33e04c48adb2af23b71ec4c633bc6b88d870c1d61a56exe  
2024-06-28 05:51:008c13fdcfeb87abd390f487e9d51d7edcdd6073951a5f96e5c0b1f7d899874932exe 
2024-06-28 05:40:3347a817f85453e16e52d201810fd5a719a1fcb01c49dfd350a2fc36fef42ac442exe 
2024-06-28 05:29:0947a817f85453e16e52d201810fd5a719a1fcb01c49dfd350a2fc36fef42ac442exe 
2024-06-28 05:24:06a2e4f1eead7d430cf08d33e04c48adb2af23b71ec4c633bc6b88d870c1d61a56exe  
2024-06-28 05:24:068c13fdcfeb87abd390f487e9d51d7edcdd6073951a5f96e5c0b1f7d899874932exe 
2024-06-28 05:24:0624f6c1b06912c2d8d46c6ac10737fd8efaaf7d18b227279f9dae584a5625c0c6exe  
2024-06-28 05:24:0647a817f85453e16e52d201810fd5a719a1fcb01c49dfd350a2fc36fef42ac442exe 
2024-06-28 05:24:068491781afed15ad4fa80b176c3516cd3b44e7880a559ab22899b216be74cec48exe  
2022-05-28 14:09:26672fea64c92edc4d937d3132577b65813738bfddeab6a6b3ef35e6fa4b987009exeAZORult
2022-04-15 13:50:33df4876573295b4e7beb618db31a015ea617f61b811978bb168d432c4052f7731exeAZORult
2022-04-13 09:26:59061e909af36cb01231742d642ca8cb8af320cbdd2d87db271921f99e2ce41a52exe 
2022-04-12 06:58:31fb368927d9051a0ed52610ad43849d1b0cdf2acee3bb1bf88c63e3fce54a4f0fexeAZORult
2022-04-11 10:01:050f63b4b4659449eee766610af817b786e9cd7622743851cf7b71430613d7521bexeRedLineStealer