URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ubsco.uk
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-08-27 06:34:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :32

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-03 04:50:58 34.41.139.193193.139.41.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USyes
2022-08-31 04:26:56 212.32.237.101Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2022-08-21 22:45:47 23.82.12.31Not listedAS30633 LEASEWEB-USA-WDC- USno
2022-08-22 12:05:33 212.32.237.91Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2022-08-22 01:54:07 212.32.237.90Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2022-08-24 17:16:00 212.32.237.92Not listedAS60781 LEASEWEB-NL-AMS-01- NLno
2022-09-18 07:34:22 23.82.12.29Not listedAS30633 LEASEWEB-USA-WDC- USno
2022-08-25 09:54:57 23.82.12.30Not listedAS30633 LEASEWEB-USA-WDC- USno
2022-08-23 13:11:34 23.82.12.32Not listedAS30633 LEASEWEB-USA-WDC- USno
2022-05-31 11:16:09 81.17.18.196hostedby.privatelayer.comNot listedAS51852 PLI-AS- CHno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-08-27 06:34:09http://ubsco.uk/o/ott.exeOfflineexe RedLineStealer ext vxvault
2021-08-27 06:34:09http://ubsco.uk/o/Console.exeOfflinebitrat ext exe vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-27 06:34:08c9a8e3393883f4ad504e595896a758d920b4199bf285a86958929c1174440425exe RedLineStealer
2021-08-27 06:34:087e91804516bd4803c7334e8bb593aa9d3f5f2b5d0160161ba4a81a4bb2556e00exeBitRAT