URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ufficiolink.top
Domain registrar:Eranet -
Domain registration date:2022-02-27 19:06:04 UTC
Abuse complaint sent to registrar: Yes (2022-02-28 08:36:02 UTC to info{at}todaynic[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2022-02-28 08:36:02 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-28 08:32:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-02-28 08:32:07 62.173.138.116ilyin091020.example.comNot listedAS34300 SPACENET-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-28 08:32:09http://ufficiolink.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep
2022-02-28 08:32:07https://ufficiolink.top/login.txtOfflinegeofenced Gozi ext inps ISFB ext ITA ursnif ext reecdeep

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-01 04:24:1423197fc4ac72c26b7f4214a75643162cbd46bde7d5a39424a3db897c3737ce6aexe Gozi
2022-03-01 01:57:34ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9eexe Gozi
2022-03-01 00:40:117e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7exe Gozi
2022-02-28 23:27:2315d777f5ae2fb7054d3db94630980e254ebb8ee92d7554d6c90e16b525131fd3exe Gozi
2022-02-28 22:25:1162d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62exe Gozi
2022-02-28 21:23:28fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6eexe Gozi
2022-02-28 20:16:2937958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3exe Gozi
2022-02-28 19:01:445e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edexe Gozi
2022-02-28 17:46:35f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268exe Gozi
2022-02-28 16:09:01c5352dbe290d56ffd51e9b957f51ebd00c6c8a0788c8357cc1dd0cf9ad8880f7exe Gozi
2022-02-28 14:43:18cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429exe Gozi
2022-02-28 13:41:55fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684aexeGozi
2022-02-28 12:18:29817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323exe Gozi
2022-02-28 11:04:34e57b6ea5d609740b8328626137a4c6b0254b33bc192d6b54c475fef2a9e3c07aexe Gozi
2022-02-28 10:01:272fc0767c71c977781d828aee42fdca19b72a38437430c13475bad8d17d0008f5exe Gozi
2022-02-28 08:32:08bce53e9e5af3e93c647956fd2fe0662e507513c7a3abee2fbc3bcb2f85432406exeGozi