URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: universalmovies.top
Domain registrar:NameSilo -
Domain registration date:2023-10-20 01:06:26 UTC
Abuse complaint sent to registrar: Yes (2024-03-02 14:38:31 UTC to abuse{at}namesilo[dot]com)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2024-03-02 14:38:31 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-02-14 11:31:17 UTC
Total malware sites :30
Online malware sites :0 (0%)
Offline Malware sites :30 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-03-08 10:12:34 104.21.74.191Not listedAS13335 CLOUDFLARENETn/ano
2024-03-08 10:12:29 172.67.162.95Not listedAS13335 CLOUDFLARENETn/ano
2024-03-08 09:24:36 91.195.240.123Not listedAS47846 SEDO-AS- DEno
2024-02-14 11:31:23 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2024-02-14 11:31:23 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2024-02-22 20:11:50 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2024-02-22 20:11:50 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano
2024-02-19 09:34:57 188.114.96.7Not listedAS13335 CLOUDFLARENETn/ano
2024-02-19 09:34:57 188.114.97.7Not listedAS13335 CLOUDFLARENETn/ano
2024-02-14 17:21:28 188.114.96.0SBL686925AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-06-25 12:19:08https://universalmovies.top/nelb.docOfflinedoc Formbook ext NDA0E
2024-06-25 12:19:08https://universalmovies.top/nelb.scrOfflineFormbook ext scr NDA0E
2024-06-25 05:14:05https://universalmovies.top/sammy.docOfflineRTF zbetcheckin
2024-06-25 05:13:05https://universalmovies.top/DOC.exeOffline64 exe Formbook ext zbetcheckin
2024-06-24 16:00:13https://universalmovies.top/ExtExport2.exeOfflineexe RedLineStealer ext abuse_ch
2024-06-24 16:00:12https://universalmovies.top/notorious.docOfflinedoc RedLineStealer ext abuse_ch
2024-06-06 06:23:06https://universalmovies.top/obiz.scrOffline32 AgentTesla ext exe zbetcheckin
2024-06-06 00:57:06https://universalmovies.top/obizx.docOfflineAgentTesla ext RTF zbetcheckin
2024-06-06 00:53:07https://universalmovies.top/john.docOfflineFormbook ext RTF zbetcheckin
2024-06-05 12:25:07https://universalmovies.top/john.scrOfflineexe Formbook ext vxvault
2024-05-30 11:59:05https://universalmovies.top/nelbin.scrOfflineexe Formbook ext abuse_ch
2024-05-23 18:24:09https://universalmovies.top/sharonzx.exeOfflineexe Loki ext abuse_ch
2024-05-22 19:06:06https://universalmovies.top/pbin.scrOfflineexe abuse_ch
2024-05-20 07:08:08https://universalmovies.top/loudzx.scrOfflineexe Formbook ext abuse_ch
2024-05-18 17:47:04https://universalmovies.top/shengzx.scrOfflineexe abuse_ch
2024-05-13 13:27:10https://universalmovies.top/micromzx.scrOfflineAgentTesla ext OriginLogger James_inthe_box
2024-05-11 05:25:11https://universalmovies.top/anon.exeOffline32 AgentTesla ext exe zbetcheckin
2024-05-10 07:51:08https://universalmovies.top/sharozx.scrOfflineexe Loki ext abuse_ch
2024-05-09 06:27:07https://universalmovies.top/scree.scrOfflineexe Loki ext abuse_ch
2024-05-02 13:51:07https://universalmovies.top/opp.scrOfflineFormbook ext James_inthe_box
2024-04-30 06:41:15https://universalmovies.top/findpeacebin.scrOfflineexe Formbook ext abuse_ch
2024-04-30 06:22:09https://universalmovies.top/teebin.scrOfflineexe Formbook ext abuse_ch
2024-04-19 05:31:09https://universalmovies.top/TransactionSummary_...Offline32 AgentTesla ext exe zbetcheckin
2024-04-18 08:51:07https://universalmovies.top/o9RbXKF6ZJDK949.scrOfflineexe Formbook ext abuse_ch
2024-04-15 05:33:06https://universalmovies.top/Tinamous.vbsOfflineAgentTesla ext GuLoader ext vbs abuse_ch
2024-04-09 09:51:06https://universalmovies.top/tdpzx.scrOfflineRemcosRAT ext Cryptolaemus1
2024-03-01 14:39:08https://universalmovies.top/errorpage/catzx.scrOfflineexe NanoCore ext rat Cryptolaemus1
2024-02-19 10:14:07https://universalmovies.top/pages/morezx.exeOfflineexe PureLogStealer RedLineStealer ext abuse_ch
2024-02-14 13:11:17https://universalmovies.top/pages/parkazx.exeOfflineAgentTesla ext exe abuse_ch
2024-02-14 11:31:23https://universalmovies.top/pages/binzx.exeOfflineexe Formbook ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-06-26 00:22:290eb63b2464eb65ad5c2dad2881dadeb3c50da801b1b6846c07710dbd4cfb4c9aexe  
2024-06-25 12:19:0813bc94a2f39a03f509036ff58462b974c401cac0df52cce22223114f909b2f72rtfFormbook
2024-06-25 12:19:087392b6a710583060d7f5bd8a3a7573fa0f278a543f961057fec04445d017de3bexeFormbook
2024-06-25 06:16:34aac7bf87da369ad526524916a28af4c42f667452178b20b3629d8ad7a227afbartf 
2024-06-25 06:12:57f783322d824a009bdcdf0ecfc1065d5039bf39c67321aedb81241eba942e2b78exeFormbook
2024-06-24 16:00:13b5e250a95073b5dfe33f66c13cc89da0fc8d3af226e5efb06bb8fcfd9a4cd6ecexeRedLineStealer
2024-06-24 16:00:12bf89362748b9e66c11aaa49ddf83b1665fe038d04225b36de4f26cffc11a0f3drtfRedLineStealer
2024-06-08 17:36:27b709ac26b95865d57eea39afb5c214bb8211b393b0abe61fb427fefe2c3d94daexe Formbook
2024-06-07 02:08:42176d8df80b1c7e74ea85fe66542a854686f89fc959e94668970e8027b27d5c7fexe Formbook
2024-06-06 17:01:2140adea3aa67619d4b840d21a1003f9701f773ae1da21f66c116665e73504cc2eexe Formbook
2024-06-06 06:23:064aa30540e4a15e91219f2531911bcc7cb2f122ab3fa8772140fe93af904f3babexeAgentTesla
2024-06-06 00:57:05d4a63dcfd079396e2b4aec12444dffb34c86afa42b0a39bc48660d8e0dc917a7rtfAgentTesla
2024-06-06 00:53:07253d732012dd416def18ed352ede88272a0ed42d2e1d3ca27ad9b3c4bcb59af0rtfFormbook
2024-05-23 19:11:515b1b715cb6affcca630d5ab5e74527b2827aaec4e8c386a229c8960f4ec6b315exe Loki
2024-05-23 18:24:0966e4c065666fc203efec41f2ac9fb171f0ad5da06c1830458ff2642ea64e789fexeLoki
2024-05-20 07:08:08598c9ee3a50b02b46197c90c5b4b01542225dd6a38059b32e326930a2798c496exeFormbook
2024-05-13 13:27:10e89f30e4e2bb0c61f89cb3a321043d10d305413954da2464c28c5606cc12656eexeAgentTesla
2024-05-11 05:25:10cde39fb9a088bc187ed6b7c412d47420114ac9303e0aee4523066f62783a2f46exeAgentTesla
2024-05-10 07:51:073c3cedc000a25a9478e78e2a90b3310afec83616d36f9353be0721dd2aa052f8exeLoki
2024-05-09 09:01:47dab1d46327d46ccbade543f499379b66a9c71a392e96f3aa29f988301bc8b656exeLoki
2024-05-09 06:27:07c3338e8d8bb652e897c624f3380e1432eb1c4c93091b64dd28abc3cfa02fa804exeLoki
2024-05-02 13:51:068ec69eaf10a3043817f153a9ac99d113884d1fe657709b759512b688c5014b8fexeFormbook
2024-04-30 09:02:212e55e38d5cae5148edb4f33ce7c9e4f9f972876803bf2ba52ba36addfec6d103exe Formbook
2024-04-30 08:53:27de8d64950f8f7c2814676455289ad297248cd4d788500d578b1a2a06e7f7b60bexe Formbook
2024-04-30 06:41:158c0807d8c9575f18be8c18aa21f0b47e2b104fe4d0a3f942f215d91ffa1d2140exeFormbook
2024-04-30 06:22:09e32e406cbf689164136fc229bf5a7127fdbb33e5e5eb636f4fca0dcbb9f6f5dcexeFormbook
2024-04-19 05:31:0999677c9af723d0773f67fe035205dbbd9d857022b1619fc33fd83808072d2caaexeAgentTesla
2024-04-18 08:51:07bafe3979cf8761e4f305509427099ef0e6193ce077236e31540aff4c47ddc74cexeFormbook
2024-04-09 18:26:3961d36494c0c51a0c0a1fcad1f36c901a6debcc3c0061f2544a01c65c688e5c03exe RemcosRAT
2024-04-09 09:51:06e9572c9f7e9e395025837bce834ffa5694f39e7c7646b7a309bad4efe31aedafexeRemcosRAT
2024-03-01 14:39:083ba9eab166460c7654150897e277fc794361493b3d4e4edd917e0ab22b6dbe6eexeNanoCore
2024-02-20 10:57:470f211c60b1024b550de24bf2a3a81809c3c5787591bf7d1f0f6b9e22a49d214fexeRedLineStealer
2024-02-20 09:30:539350159172ef52b17346dc31395e060835ada39ec6f6f4e12cce7f93b9ee9560exe AgentTesla
2024-02-20 03:28:12d8ae08b49836b01761e4f4ffd307ffaccc8bd1c48fe47f55ab923b2765b2b76dexeAgentTesla
2024-02-20 02:39:467f384f810f0248e6a09b207423115499f43d5343d5fa7cbc3f985900c10109a0exeRedLineStealer
2024-02-19 10:14:07e3047ef72f547d61f94ee9922e77211c01b4cc5be23d3a45a113b04fdeb2bec2exePureLogStealer
2024-02-19 01:43:411aa8e7c903ab9354a83253ac608fc80d8269e3f45b910a60cc8a87ab631b14e3exe AgentTesla
2024-02-19 00:43:26fb9422901a6a8d8e2b60eb53159fef0de70b0c6260202c9d3fc8e8f6270b9a74exe AgentTesla
2024-02-14 13:11:1720cf4c65d87c78a7f04664974de125697792c6381d028ae32ec275294edae5cfexeAgentTesla
2024-02-14 11:31:23ce844a8fbd6db8142fff6b159a970d1f6156dda1dd758828e5e8755ab7a922cbexeFormbook