URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ring1.ug
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-10-18 22:52:02 UTC
Total malware sites :21
Online malware sites :0 (0%)
Offline Malware sites :21 (100%)
A record(s) observed :9

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-11-17 10:44:21 147.139.139.85Not listedAS45102 ALIBABA-CN-NET- IDno
2019-11-14 22:10:39 79.143.31.155d6w1lsxe5t0l25r2.comNot listedAS50340 SELECTEL-MSK- RUno
2019-11-13 21:05:49 80.249.144.103dobuvdd3vcmtoppl.comNot listedAS49505 SELECTEL- RUno
2019-11-07 15:22:38 5.53.124.119003165402.cartaprecatoria.onlineNot listedAS49505 SELECTEL- RUno
2019-11-01 08:17:47 5.101.51.166d78rviskh0srcxcz.comNot listedAS49505 SELECTEL- RUno
2019-10-31 09:22:17 47.254.236.255Not listedAS45102 ALIBABA-CN-NET- MYno
2019-10-30 10:08:31 194.67.90.77194-67-90-77.cloudvps.regruhosting.ruNot listedAS197695 AS-REGRU- RUno
2019-10-29 11:02:29 5.53.124.8debucksnewlawnsodfarm.comNot listedAS49505 SELECTEL- RUno
2019-10-18 22:52:06 47.74.190.146Not listedAS45102 ALIBABA-CN-NET- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-11-11 23:31:05http://ring1.ug/exe/starticon9.exeOfflineArkeiStealer ext exe stop p5yb34m
2019-11-07 21:48:11http://ring1.ug/files/cost/updatewin1.exeOfflinedjvu ransom P3pperP0tts
2019-11-07 21:48:09http://ring1.ug/files/cost/updatewin2.exeOfflinedjvu ransom P3pperP0tts
2019-11-07 21:48:08http://ring1.ug/files/cost/updatewin.exeOfflinedjvu ransom P3pperP0tts
2019-11-07 21:48:06http://ring1.ug/files/cost/3.exeOfflinedjvu ransom P3pperP0tts
2019-11-07 21:48:04http://ring1.ug/files/cost/4.exeOfflinedjvu ransom P3pperP0tts
2019-11-06 14:31:06http://ring1.ug/files/penelop/5.exeOfflineArkeiStealer ext exe oppimaniac
2019-11-06 13:21:03http://ring1.ug/exe/starticon11.exeOfflineArkeiStealer ext exe zbetcheckin
2019-11-06 13:17:09http://ring1.ug/exe/starticon4.exeOfflineArkeiStealer ext exe zbetcheckin
2019-11-06 13:17:06http://ring1.ug/exe/starticon8.exeOfflineArkeiStealer ext exe zbetcheckin
2019-11-06 13:17:03http://ring1.ug/exe/starticon10.exeOfflineArkeiStealer ext exe zbetcheckin
2019-11-06 13:16:06http://ring1.ug/exe/starticon6.exeOfflineArkeiStealer ext exe zbetcheckin
2019-11-06 13:12:06http://ring1.ug/exe/starticon12.exeOfflineArkeiStealer ext exe zbetcheckin
2019-10-27 20:24:13http://ring1.ug/exe/starticon3.exeOfflineexe stop zbetcheckin
2019-10-27 20:24:08http://ring1.ug/exe/starticon1.exeOfflineArkeiStealer ext exe zbetcheckin
2019-10-27 20:20:05http://ring1.ug/exe/starticon2.exeOfflineArkeiStealer ext exe zbetcheckin
2019-10-27 20:15:06http://ring1.ug/files/cost/5.exeOfflineArkeiStealer ext exe zbetcheckin
2019-10-27 20:11:06http://ring1.ug/exe/starticon.exeOfflineArkeiStealer ext exe zbetcheckin
2019-10-18 23:04:06http://ring1.ug/files/penelop/updatewin.exeOfflineexe zbetcheckin
2019-10-18 22:56:07http://ring1.ug/files/penelop/updatewin1.exeOfflineexe zbetcheckin
2019-10-18 22:52:06http://ring1.ug/files/penelop/updatewin2.exeOfflineexe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-11-17 16:32:56c772d3cc812cd0cd7bb62b002df3be654574098a3ef4683cb5c807bcbbe8b861exe ArkeiStealer
2019-11-17 16:32:38c772d3cc812cd0cd7bb62b002df3be654574098a3ef4683cb5c807bcbbe8b861exe ArkeiStealer
2019-11-17 10:44:5025ae21623bc8f9b7788ac0cad7ff89dea59435e7819144173a61a0561897e42bexe ArkeiStealer
2019-11-17 10:44:3325ae21623bc8f9b7788ac0cad7ff89dea59435e7819144173a61a0561897e42bexe ArkeiStealer
2019-11-15 11:06:0112ec970a6ba2519765a72a3ab4a832290c98ed143cbf26af698db0a93d475f10exe ArkeiStealer
2019-11-15 11:03:5012ec970a6ba2519765a72a3ab4a832290c98ed143cbf26af698db0a93d475f10exe ArkeiStealer
2019-11-14 10:13:52eaff887788222e481f3f1c494a638e60988827a3e665be6ab59daef68843b779exe ArkeiStealer
2019-11-14 10:13:28eaff887788222e481f3f1c494a638e60988827a3e665be6ab59daef68843b779exe ArkeiStealer
2019-11-12 11:54:0518334bf61f0a168c1a7246f188daf650d24b6c53f76db3685cabaf1d106da448exe ArkeiStealer
2019-11-12 11:51:4918334bf61f0a168c1a7246f188daf650d24b6c53f76db3685cabaf1d106da448exe ArkeiStealer
2019-11-11 23:31:0408b6c38e79c9ac0ce7a7fafaaae1334c41d70b860ff2c8eb6b2742c58cdb06b3exe ArkeiStealer
2019-11-09 08:46:3236213f57ceabe23ef76ec56f006c6fc1a1f03a6c94949b0f14b8e6dec26af98bexe ArkeiStealer
2019-11-09 08:46:1636213f57ceabe23ef76ec56f006c6fc1a1f03a6c94949b0f14b8e6dec26af98bexe ArkeiStealer
2019-11-06 14:31:06b00195d06350161758241dd77bbff9c8fd9ae927b1455c9ac31b36df5e3e7ad9exe ArkeiStealer
2019-11-06 13:21:034598a0c09cb160c295b10c02d3ccfb261cd728b11f4fd1d47db21702100670bdexe ArkeiStealer
2019-11-06 13:17:0902a13ebd9224c7cc323da1cd280ad86b22f2afb8ec46c5de746ce07cd872e65bexe ArkeiStealer
2019-11-06 13:17:061b359f5e2446a66b1e44143fabdfe23de8c237e93eeae0e973646dd205a645a7exe ArkeiStealer
2019-11-06 13:17:03b3fe4b11600f9d627b6e45a12eaa13759b38ba6be32be53a53660069bb842da3exe ArkeiStealer
2019-11-06 13:16:053d3df3e7eb70a5b2ec5d8484b65aa13b0bfa15161ad29b1435f17fc7c80cdef9exe ArkeiStealer
2019-11-06 13:12:067be5dde8b2e9644299e8b9db298c65449d0e6b351377533691c0f1ccc6bab1c4exe ArkeiStealer
2019-11-06 07:35:09b00195d06350161758241dd77bbff9c8fd9ae927b1455c9ac31b36df5e3e7ad9exe ArkeiStealer
2019-11-04 11:30:317b3eb4e7cad673ac4e9d3894466a15dedd45621d116e0222209b3ab98b6677c3exe ArkeiStealer
2019-11-04 11:30:3062b057020008025fdd1b9d5fe788487ef5c312b8dcae31b8edea1f41882a03f1exe  
2019-11-03 10:40:447be5dde8b2e9644299e8b9db298c65449d0e6b351377533691c0f1ccc6bab1c4exe ArkeiStealer
2019-11-02 19:41:134598a0c09cb160c295b10c02d3ccfb261cd728b11f4fd1d47db21702100670bdexe ArkeiStealer
2019-11-02 16:37:25c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83eexe ArkeiStealer
2019-11-02 10:55:27b3fe4b11600f9d627b6e45a12eaa13759b38ba6be32be53a53660069bb842da3exe ArkeiStealer
2019-11-01 09:24:3208b6c38e79c9ac0ce7a7fafaaae1334c41d70b860ff2c8eb6b2742c58cdb06b3exe ArkeiStealer
2019-10-31 14:04:351b359f5e2446a66b1e44143fabdfe23de8c237e93eeae0e973646dd205a645a7exe ArkeiStealer
2019-10-30 16:44:52e3144bdf5832d4bb313acac8d9f7869995a68ef0bc6818d73d66150eca671655exe ArkeiStealer
2019-10-30 13:49:36c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83eexe ArkeiStealer
2019-10-30 12:09:316c85336356050bf7000958c5f9be85bed2f10d5bbf8d1bb7ed1974fcfc41e9d9exe ArkeiStealer
2019-10-29 11:02:293d3df3e7eb70a5b2ec5d8484b65aa13b0bfa15161ad29b1435f17fc7c80cdef9exe ArkeiStealer
2019-10-28 15:37:12cc0d8e673a5e37b4ab405225ec313e928a1750622500884dfe0e3642a9a297acexe ArkeiStealer
2019-10-28 11:25:36f39c954c592021cf567b3bec1793399e80df0cfbf89816772f851c761c2387fbexe  
2019-10-27 20:24:137bc2928ce06e7db7bfe0bf3f2c2d2ff9df7f0a8041ea8c593dd0b912c1c3d3fdexe Ransomware.Stop
2019-10-27 20:24:082e44467717c1b09314bd7193af70683f20b0c5740f45fadbe28d5eff38690cfdexe ArkeiStealer
2019-10-27 20:20:0534745abeba30e12a9dee88bcb7c3c9b119f8c21451a2d8ab2aec298c76b35616exe ArkeiStealer
2019-10-27 20:15:067baebcacdcb750d2bb2b8e7ccc404e673a63eac7f4eb6bf48c7b787663a1094bexe ArkeiStealer
2019-10-27 20:11:0502a13ebd9224c7cc323da1cd280ad86b22f2afb8ec46c5de746ce07cd872e65bexe ArkeiStealer
2019-10-18 23:04:06114ccacb7ca57c01f3540611fdf49e68416544da8d8077f5896434a4b71b01ddexe  
2019-10-18 22:56:0714c7bec7369d4175c6d92554b033862b3847ff98a04dfebdf9f5bb30180ed13eexe 
2019-10-18 22:52:055caffdc76a562e098c471feaede5693f9ead92d5c6c10fb3951dd1fa6c12d21dexe