URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ufficiolines.top
Domain registrar:Eranet -
Domain registration date:2022-02-27 19:06:03 UTC
Abuse complaint sent to registrar: Yes (2022-02-28 08:21:02 UTC to info{at}todaynic[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2022-02-28 08:21:02 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-28 08:19:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-28 08:19:05 62.173.151.56Not listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-28 08:19:05https://ufficiolines.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep
2022-02-28 08:19:05http://ufficiolines.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-01 04:48:55e77a57a76ec227bbb2b7e5b29ebcaac5a0c0f24779984353b7bfed395e97cf6fexe Gozi
2022-03-01 01:59:21ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9eexe Gozi
2022-03-01 00:51:067e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7exe Gozi
2022-02-28 23:49:0480ce53e5dfb8260fe911f020621d7d887f9ba9c23b2b2805665016bd4383b1edexe Gozi
2022-02-28 22:48:5362d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62exe Gozi
2022-02-28 21:37:09fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6eexe Gozi
2022-02-28 20:36:0637958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3exe Gozi
2022-02-28 19:16:155e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edexe Gozi
2022-02-28 17:47:55f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268exe Gozi
2022-02-28 16:38:0854cadf62508d5b2151283b0b804cc29481df6948b2ee88867ffe13698326e8b9exe Gozi
2022-02-28 15:05:01cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429exe Gozi
2022-02-28 13:53:29fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684aexeGozi
2022-02-28 12:49:098a1667ced8247d1642ea3794e0dca340c4be3f44a5d465a47632b1946c36268eexe Gozi
2022-02-28 11:31:13817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323exe Gozi
2022-02-28 10:22:40e57b6ea5d609740b8328626137a4c6b0254b33bc192d6b54c475fef2a9e3c07aexe Gozi
2022-02-28 08:58:48bce53e9e5af3e93c647956fd2fe0662e507513c7a3abee2fbc3bcb2f85432406exeGozi
2022-02-28 08:19:05645d6e01fb304d604422c5a2812d107e21c091925fbea750c9c80542c7903399exe Gozi