URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ufficioline.top
Domain registrar:Eranet -
Domain registration date:2022-02-27 19:06:04 UTC
Abuse complaint sent to registrar: Yes (2022-02-28 07:31:02 UTC to info{at}todaynic[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2022-02-28 07:31:03 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-28 07:28:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-28 12:13:33 62.173.138.57disk.tekenergokomplekt.comNot listedAS34300 SPACENET-AS- RUno
2022-02-28 07:28:05 185.31.162.148Not listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-28 07:28:05https://ufficioline.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep
2022-02-28 07:28:05http://ufficioline.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-01 03:47:5142fbdb6312c3f44c9cc8d84b851500f78332984b253a5d435ef815a0ea0fce3aexe Gozi
2022-03-01 02:41:31ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9eexe Gozi
2022-03-01 00:12:147e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7exe Gozi
2022-02-28 22:56:5562d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62exe Gozi
2022-02-28 21:29:51fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6eexe Gozi
2022-02-28 20:27:5337958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3exe Gozi
2022-02-28 19:25:535e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edexe Gozi
2022-02-28 18:23:431b80e0aa6560bd9868c6d7a0dad54f9e66ec13f2c125ea8761f6822d88c39464exe Gozi
2022-02-28 17:10:31f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268exe Gozi
2022-02-28 16:05:43c5352dbe290d56ffd51e9b957f51ebd00c6c8a0788c8357cc1dd0cf9ad8880f7exe Gozi
2022-02-28 15:01:24cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429exe Gozi
2022-02-28 13:19:12fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684aexeGozi
2022-02-28 12:13:30817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323exe Gozi
2022-02-28 09:32:162fc0767c71c977781d828aee42fdca19b72a38437430c13475bad8d17d0008f5exe Gozi
2022-02-28 07:28:05645d6e01fb304d604422c5a2812d107e21c091925fbea750c9c80542c7903399exe Gozi