URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 32589.clmonth.nyashteam.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-09-24 04:43:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 09:45:20 104.21.2.8Not listedAS13335 CLOUDFLARENETn/ano
2025-04-27 09:45:20 172.67.186.200Not listedAS13335 CLOUDFLARENETn/ano
2023-06-25 19:09:50 91.103.252.23racial-ladybug.aeza.networkSBL655618AS211522 HYPERCORELTD- NLno
2023-03-30 12:31:55 94.142.138.11SBL655622AS211522 HYPERCORELTD- FIno
2023-03-16 21:41:37 82.115.223.199Not listedAS214927 PSB-AS- NLno
2023-02-12 16:30:34 31.47.0.165Not listedAS202632 TXtv- BAno
2023-02-26 19:39:47 5.201.13.187Not listedAS12324 LUBMAN-EDU-AS- PLno
2023-02-11 20:26:47 141.94.55.49Not listedAS16276 OVH- FRno
2023-01-25 00:29:58 103.206.112.230Not listedAS141303 DVRBS-AS- INno
2023-02-03 12:10:06 162.55.107.157server.goodkeyshop.comNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-25 13:58:18http://32589.clmonth.nyashteam.ru/lowLongpoll/6...Offlineexe Formbook ext jstrosch
2022-09-24 04:43:08http://32589.clmonth.nyashteam.ru/lowLongpoll/c...Offline32 dcrat exe zbetcheckin