URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: marcapslsa.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-29 10:23:04 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-29 10:23:06 217.8.117.77Not listedAS49505 SELECTEL- TMno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-29 10:23:06http://marcapslsa.ug/zxcvb.exeOfflineArkeiStealer ext exe RaccoonStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-06 12:22:06086f7495f2591e14daf2ee23e052937013a663d41b616738b48ef1f75f34a494exe RaccoonStealer
2020-08-31 17:32:4843289193e35ad500026942fe9da85b24142625f3dba0e26b88f646bde55a0112exe RaccoonStealer
2020-08-31 11:21:267e9b9bbb673e25ab8ee790dbfd2a3e489c0d3a88ab73aafe671f68982f1b41daexeArkeiStealer
2020-08-29 10:23:059b1328490717e1e3c97216a17bf36b67103a40dae3bbac6865487e51fea82b32exeRaccoonStealer