🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ontechrio.com
Domain registrar:Dynadot -
Domain registration date:2022-11-20 00:29:15 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-09-21 16:38:12 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-02 10:31:07 198.54.116.54host53-4.registrar-servers.comNot listedAS22612 NAMECHEAP-NET- USno
2025-11-21 17:31:46 75.2.18.233ac1a2ad24832d38a2.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-09-21 16:38:16 104.21.44.38Not listedAS13335 CLOUDFLARENETn/ano
2023-09-21 16:38:16 172.67.194.166Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-10-23 15:49:41http://ontechrio.com/ebie/OfflineTA577 TR k3dg3
2023-10-23 15:45:37https://ontechrio.com/ebie/OfflineTA577 TR k3dg3
2023-09-26 10:45:10https://ontechrio.com/cnie/OfflineDarkGate ext IcedID ext xll 0x48215333
2023-09-21 16:38:16https://ontechrio.com/fg/OfflineDarkGate ext PDF USA xll Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-10-24 04:51:5138464d8ca71e64851b267f6a6c5115fd0dd7d3c943a2c6fa8b0e2b60e0f10752zip  
2023-10-24 03:59:347d203e1e83de16ce5560d95b23ba05f5ff33d388ecd279c19b2c607e807c9e56zip  
2023-10-23 16:47:206dda42107ac8a669e60b89e9aba5140c2e5dbbef334b2f90a4c5e2b9f985504czip  
2023-10-23 15:55:344bfa92f4411f5c1efcd2e604366e4078bea75dc49325b77af24edf447da2a91bzip  
2023-10-23 15:49:41c7213631b18a43340e268cbafb6ca301596a59215aa6eb355f9d3d1edec1f9e0zip  
2023-10-23 15:45:377e46f504d0134601bc016a67e5b3d8870246ebd93ab8b732d2e649fedf127459zip  
2023-09-26 21:25:4107ed2d2badab4e7e898571612c8b09e1411ad097b9774db40f262a52f124c6aazip  
2023-09-26 14:18:464f8dd21869502ec90c17807b01ffc5aaf9b7f325f3840bd4288f5de9e5efe2a9zip  
2023-09-26 11:40:013dc30d6e7dac7811b7894083cb91c7686813bcb5d47ea708cef6dc68a2d479e0dll IcedID
2023-09-26 10:46:552c41bcc572fdf4a90604fa6188fb3f4f646c521f604109a6b6dd130f6f3d46c3dll IcedID
2023-09-22 01:48:17091b7c16791cf976e684fe22ee18a4099a4e26ec75fa145b85dd14603b466b00dll DarkGate
2023-09-21 21:24:3098c59262ad396b4da5b0a3e82f819923f860e974f687c4fff9b852f25a56c50fdllDarkGate
2023-09-21 18:36:06392fd4d218a8e333bc422635e48fdfae59054413c7a6be764c0275752d45ab23dll DarkGate
2023-09-21 18:00:27305de78353b0d599cd40a73c7e639df7f5946d1fc36691c8f7798a99ee6835e7dll DarkGate
2023-09-21 16:38:159a34b32d0a66dd4f59aeea82ef48f335913c47c6ca901ab109df702cd166892fdll DarkGate