URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.gestroom.it
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-03-02 20:17:17 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-02 20:17:20 80.88.87.130linp078.arubabusiness.itNot listedAS31034 ARUBA-ASN- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-02 20:17:20https://www.gestroom.it/Offlinecensys ClickFix FakeCaptcha html NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-03 06:32:47ebfb4e09ef64d8491058b180cddf0b9c40188fa3cd0c5ac86b4acbda3219d2cchtml  
2026-08-03 04:21:54fafd1b79489cb7041f82261e7e55277846bd897ce6e950d15ac9a369c506f208html  
2026-08-02 19:55:4717fbe9f000007364d47160baaa410b668f9408cdb0c19ceb7282ff3e3a0c0bf8html  
2026-08-02 08:22:32b97c6d152459a98e178d6928fb23a57c84f7a0ef5a94c98a0072a7ac6651e512html  
2026-08-01 07:35:20fb30af9c14015ec31a33e80a1cd447e280e18cc613b1f2099993e44beb646feahtml  
2026-07-31 14:31:083d75b1f2a9da03af3847a32168bd69309c8585117f91f9027a9adec4b72d5355html  
2025-03-02 20:17:20c3baf1eaa63000020bdae8ecec6636b79adaefa6b290480d94959b54666f1ca7html