URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: uiu-auzq5.tk
Abuse complaint sent?: Yes (2022-10-28 06:05:02 UTC to abuse{at}freenom[dot]com)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-10-28 06:00:10 UTC
Total malware sites :23
Online malware sites :0 (0%)
Offline Malware sites :23 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-28 06:00:11 162.144.81.198162-144-81-198.unifiedlayer.comNot listedAS46606 UNIFIEDLAYER-AS-1- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-28 06:00:14https://uiu-auzq5.tk/n/HDFFHXGHFHHFJHHJ.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/nn/NMXCJKHKDFDF.exeOfflineexe RemcosRAT ext jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/nn/BGHkKHH.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/BCDGFJFJGHKJK.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/nn/VXCVNCXVJGKKFD.exeOfflineexe RemcosRAT ext jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/BBGHJJjJIJKKg.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/BHGgTtTtgtG.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/SHIKLPLKMNBH.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/VMNCXJFDJK.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/nn/VBXCVMJJKD.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/VNVVCXJKJJKDFS.exeOfflineAsyncRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/nn/DFGHHDJFDDFDFJDJ.exeOfflineAsyncRAT ext exe jstrosch
2022-10-28 06:00:14https://uiu-auzq5.tk/n/MNZCVNCJKG.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/nn/MMarry.exeOfflineexe Formbook ext jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/n/HHkPoJhH.exeOfflineAveMariaRAT ext exe jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/nn/BVXCBCNXVCXJGJGDF.exeOfflineAgentTesla ext exe jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/n/HFMN,N,JGHJH.exeOfflineexe Formbook ext jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/nn/lamb.exeOfflineexe RedLineStealer ext jstrosch
2022-10-28 06:00:13https://uiu-auzq5.tk/nn/HKFKHDFKDF.exeOfflineexe Formbook ext jstrosch
2022-10-28 06:00:12https://uiu-auzq5.tk/nn/NHgHIoPPKOI.exeOfflineexe Formbook ext jstrosch
2022-10-28 06:00:12https://uiu-auzq5.tk/nn/BCHDHDDH.exeOfflineAgentTesla ext exe jstrosch
2022-10-28 06:00:12https://uiu-auzq5.tk/nn/BNDSDSHHD.exeOfflineexe Formbook ext jstrosch
2022-10-28 06:00:11https://uiu-auzq5.tk/nn/mary.exeOfflineexe Formbook ext jstrosch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-28 07:58:16bbef7e02b36b3ffc1444e1442c321878bfaf8b6719abe3c5afcb769a16581f6eexeFormbook
2022-10-28 06:00:1476da8d019d495060463d0574cbcabb75ebbbd17c949cc45e7c55bf805e09c27dexeAveMariaRAT
2022-10-28 06:00:148f6954e1834b49a24b8e937ff093f1e534f89691ce805ce2f14553315a18e651exeRemcosRAT
2022-10-28 06:00:14237803281430a3e53b0f8f3ac3504dd95fbc9cf4f9cd7d803db0227a0c849388exeAveMariaRAT
2022-10-28 06:00:1445e729e5927a102945f848d00283c3f43196d0e03a0a8ad9afeeff6f350a24bfexeAveMariaRAT
2022-10-28 06:00:140a6b4d008994bb06574688d817089831fc7404e5e458c38e7a1464d072a8fd7aexeRemcosRAT
2022-10-28 06:00:14fc26b253c7a3a6cc7711b511ad8e6346caf88344f1b8b5c924c9e008ecaa0c8cexeAveMariaRAT
2022-10-28 06:00:149d299bff3a3e78f7136c577564acd318345e6bb400a3c6c9fda75e3c1476a856exeAveMariaRAT
2022-10-28 06:00:147e96a60f26b252ef89a4e1f3fb4264f224031f6d8c9bc592f3ec715a3307c679exeAveMariaRAT
2022-10-28 06:00:14a32dc1a41c102124b6d7d7c1ac5790870a6a49d8f2133008797132ac2ac82498exeAveMariaRAT
2022-10-28 06:00:14a67b8abcd5494b8616dbc6cc982d9aecdf0fb33c4183686f762d2242e6428efcexeAveMariaRAT
2022-10-28 06:00:14a6d842756717a7bb3bc7e9c917be8c1cebfdf6aea4ca7179e4c1a0f145fc25b7exeAsyncRAT
2022-10-28 06:00:1445f001fd475696ab175ad503361099a3c07c0a08da930f5c3b9e12969c9aa0eeexeAsyncRAT
2022-10-28 06:00:1413f63988f5e56f67d8a0c4751298e1f6eb09cbdbd92b35556fe39b414b493594exeAveMariaRAT
2022-10-28 06:00:13d24dd6cd68f406d083ebc0690537254dcaabfd26ef4987dd6c2cc99c29be277eexeAveMariaRAT
2022-10-28 06:00:13610749802e2c335b72c844844035cfd854c49b7ea5b5e8a85ef8cfc3f629377dexeFormbook
2022-10-28 06:00:123848823a1b58d846e410636a0f7fe39ab04c984fe8353489e4d83f694195e26eexeFormbook
2022-10-28 06:00:12751e97d79511338f167c15ce971bb790c685a72d7dc1598a50b126099592c496exeAgentTesla
2022-10-28 06:00:12cfcae7aaa384f20d0b16577e2ac81010403db19bec0fe546ec6fc0a7cf2d3d09exeRedLineStealer
2022-10-28 06:00:1288ade6643c996e0629957b5d89927296f32d850dbca7ed18b973c0d37134e371exeFormbook
2022-10-28 06:00:12d915094865ca0d36398957538ca6afb7c59354d1ff13676c8032470986c7db9bexeFormbook
2022-10-28 06:00:12c2b9f5381f93b30000524351d0ab8b09c675ea0e8df3d14ff897044655f98affexeAgentTesla
2022-10-28 06:00:11f53340a00d5248f81164bd5a1880698c4926cf62dc2fc5c93696f87780733b1aexeFormbook
2022-10-28 06:00:11a75fa828c957b6b8a85cc40bf4a0a64fb6afef7ef1fe31dc0e842baf399031beexeFormbook