URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: rainbirds.ac.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-05-19 20:57:09 UTC
Total malware sites :1
A record(s) observed :13

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-27 17:08:30 217.8.117.45Not listedAS49505 SELECTEL- TMno
2020-05-27 08:17:39 49.51.134.20Not listedAS132203 TENCENT-NET-AP-CN- DEno
2020-05-27 02:56:54 62.113.118.219host-62-113-118-219.hosted-by-vdsina.ruNot listedAS48282 VDSINA-AS- RUno
2020-05-25 22:44:34 162.62.53.243Not listedAS132203 TENCENT-NET-AP-CN- DEno
2020-05-27 01:32:14 47.241.1.122Not listedAS45102 ALIBABA-CN-NET- SGno
2020-05-25 21:29:38 5.53.124.243thedacxi.comNot listedAS49505 SELECTEL- RUno
2020-05-25 11:21:19 101.32.5.54Not listedAS132203 TENCENT-NET-AP-CN- HKno
2020-05-25 08:45:20 80.249.147.104drx3xtxi3d9pjp04.comNot listedAS49505 SELECTEL- RUno
2020-05-25 07:32:46 8.208.88.203Not listedAS45102 ALIBABA-CN-NET- GBno
2020-05-23 05:36:01 195.140.146.65default.clo.ruNot listedAS29182 RU-JSCIOT- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-05-19 20:57:11http://rainbirds.ac.ug/zxcvb.exeOfflineArkeiStealer ext AZORult ext exe RaccoonStealer ext zbetcheckin