URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | rabbids.cc |
|---|---|
| Domain registrar: | NICENIC ![]() |
| Domain registration date: | 2026-09-18 14:27:19 UTC |
| Abuse complaint sent to registrar: | Yes (2026-09-28 06:16:03 UTC to support{at}nicenic[dot]net) |
| Domain registry: | VeriSign Global Registry Services
![]() |
| Abuse complaint sent to registry: | Yes (2026-09-28 06:16:03 UTC to info{at}verisign-grs[dot]com) |
| Spamhaus DBL : | Malware domain |
| SURBL : | Not blocked |
| Quad9 : | Blocked |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Not blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2026-09-28 06:11:16 UTC |
| Total malware sites : | 5 |
| Online malware sites : | 2 (40%) |
| Offline Malware sites : | 3 (60%) |
| Newest active malware site : | 2026-09-28 06:11:20 UTC |
| Oldest active malware site : | 2026-09-28 06:11:19 UTC (Age: 12 days, 5 hours, 22 minutes) |
| A record(s) observed : | 1 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-09-28 06:11:19 | 196.251.107.72 | SBL678968 | AS214351 FEMOIT | DE | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2026-09-28 06:11:20 | https://rabbids.cc/encrypted/7za.exe | Online | component dll-sideloading exfiltration infostealer Lzveil stealer surveillance tool Yogi c2 dropper zip | |
| 2026-09-28 06:11:20 | https://rabbids.cc/start.php | Offline | component dll-sideloading exfiltration infostealer Lzveil stealer surveillance tool Yogi c2 dropper zip | |
| 2026-09-28 06:11:19 | https://rabbids.cc/end.php | Offline | component dll-sideloading exfiltration infostealer Lzveil stealer surveillance tool Yogi c2 dropper zip | |
| 2026-09-28 06:11:19 | https://rabbids.cc/screen.php | Offline | component dll-sideloading exfiltration infostealer Lzveil stealer surveillance tool Yogi c2 dropper zip | |
| 2026-09-28 06:11:19 | https://rabbids.cc/encrypted/1.zip | Online | component dll-sideloading exfiltration infostealer Lzveil stealer surveillance tool Yogi c2 dropper zip |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-10-09 17:07:36 | 952017f6382eb6917e7f554a6d49ac508fe0e64467b6395c72ec2fad296078eb | zip | ||
| 2026-10-05 23:01:39 | 0beeef35e921cf13d44ad57efb2707d1ecba8e08cd60193a00dc115c8a773998 | zip | ||
| 2026-10-05 00:12:41 | aa24fe14969327dca3d613f3987e9af2e5d464cac751baa0ba8d1df6cd915085 | zip | ||
| 2026-10-04 11:22:08 | 093c945356a83028d6c347ce06280ef6a30f32c511beba0ef77e4c9db50af4de | zip | ||
| 2026-10-02 18:00:41 | e72ab84bec9a7d4428f1b1f38f335666d45cc4e2c7d97f0de250c7dae1d8ea17 | zip | ||
| 2026-10-01 23:18:02 | 1d2284f75518ffdefd2a7c2daaf0d83b75786e7e85aed169403ba54aa427847f | zip | ||
| 2026-09-29 22:50:51 | c1d76e38446ae7f4430b2d622befac3f66057d523eb26d3507c14dcb825b5af5 | zip | ||
| 2026-09-28 11:10:28 | adc82a6c848faa52c7d3d37fa9f2fe01eecbd85a1707e670e494d510cd3c9100 | zip | ||
| 2026-09-28 06:11:19 | cb5a2fbe974d5ff30b4d6e55d7c0066147974b0525ee27176e83c2fd158e2ba6 | zip | ||
| 2026-09-28 06:11:19 | bfb34635f295df13ea1677c0d51d08fafd2da21a1c0bea252df6342d40e511a0 | exe |


DE