URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 6yd.ru
Domain registrar:R01 -
Domain registration date:2025-10-08 15:03:27 UTC
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-11-24 09:01:07 UTC
Total malware sites :20
Online malware sites :18 (90%)
Offline Malware sites :2 (10%)
Newest active malware site :2025-11-28 17:57:16 UTC
Oldest active malware site :2025-11-24 09:01:17 UTC (Age: 4 days, 13 hours, 19 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-24 09:01:17 103.146.23.141Not listedAS131366 LANIT-AS-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-28 17:57:16http://6yd.ru/mpslOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/arm4Onlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/armOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/arm5Onlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/mipsebOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/aarch64Onlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:14http://6yd.ru/x86Onlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:13http://6yd.ru/massloadOnlinebotnetdomain sh ua-wget BlinkzSec
2025-11-28 17:57:13http://6yd.ru/harm5Onlineelf ua-wget BlinkzSec
2025-11-28 17:57:13http://6yd.ru/tvtOnlinebotnetdomain sh ua-wget BlinkzSec
2025-11-28 17:57:13http://6yd.ru/wget.shOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-11-28 17:57:13http://6yd.ru/adb.shOnlinebotnetdomain sh ua-wget BlinkzSec
2025-11-28 17:57:11http://6yd.ru/ftpget.shOfflinebotnetdomain sh ua-wget BlinkzSec
2025-11-28 17:57:11http://6yd.ru/tftp.shOfflinebotnetdomain sh ua-wget BlinkzSec
2025-11-28 17:57:10http://6yd.ru/mipselOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:10http://6yd.ru/powerpcOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:10http://6yd.ru/arm7Onlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:10http://6yd.ru/arcOnlineelf mirai ext ua-wget BlinkzSec
2025-11-28 17:57:09http://6yd.ru/curl.shOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-11-24 09:01:17http://6yd.ru/mipsOnline32-bit elf mirai ext Mozi ext threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-28 17:57:165add3655c138947e54f6e93f583e7704a9a33ea87a1c76eb5322358d9d6d992eelfMirai
2025-11-28 17:57:14fe97cfdc07d40ad61d688edb30b6d7fdb500c0d6db85f7d1f9e639173922f4abelfMirai
2025-11-28 17:57:14fe97cfdc07d40ad61d688edb30b6d7fdb500c0d6db85f7d1f9e639173922f4abelfMirai
2025-11-28 17:57:1379669de0d033988a50ce5e69715f1aa1a0a7a41b7d5870fb84d80f63fc509bb7shMirai
2025-11-28 17:57:135b94659fba807f800bca96cbf40d6be1da4306e21b0f6f2579c41f70585690e9elfMirai
2025-11-28 17:57:13a1c3941f2e6e7a2099d4cceb16d574744904ec24c0b83e7aef9e34140d7e18d6elfMirai
2025-11-28 17:57:13ff99ce00e0e3cdefd3dc2c742a7f0edb84f1cf588656eb6494e7ee3b6a961b34elfMirai
2025-11-28 17:57:1386b6d6e282d0c889d7e97e6414672b37cbcb016d8f133212958a9b3af90c53e5elfMirai
2025-11-28 17:57:13c427d6dd3221bc88ca9a329afd481f63f8387010e5785bbe4e524ff795710b1eelf 
2025-11-28 17:57:13b60993f256efd7d2c14ddbe164ef7e1dbf4f9917fd84b7f58e42b75fd9913fbash 
2025-11-28 17:57:136d29e4352ae66c81057ee4ca4434857ca062ca4617442d969acd42adf46de0e8sh 
2025-11-28 17:57:1380748692d7d5c1490d0d0f39c69f7266d71a39e1c598d7b20922b189141220f8sh 
2025-11-28 17:57:105add3655c138947e54f6e93f583e7704a9a33ea87a1c76eb5322358d9d6d992eelfMirai
2025-11-28 17:57:10102596c6c0ac0201bb8eff29e1e210540f192026927a79e23d27b11dc25e4b33elfMirai
2025-11-28 17:57:1021c9e1189e8447ddb5e233401d47ac4be0321d988e081a75a074d4414cf1a5a8elfMirai
2025-11-28 17:57:10a9d8866d67bc45b182afc8fc328ff62c4ea38eca529d2ebc8734dfbbdf736273elfMirai
2025-11-28 17:57:092005930349994dd3f359d3c1cb9f333587d00dbb0419637a4d6337e976587778shMirai
2025-11-28 16:04:548940a2d83740ea74154a6ede90488eb87e10ca22f092597e9c27f00ae380f8cbelfMirai
2025-11-28 16:04:468940a2d83740ea74154a6ede90488eb87e10ca22f092597e9c27f00ae380f8cbelfMirai
2025-11-28 05:56:1088524a1cf45708d2b3d2236149e325b8db71d2aeaa46e4fd3a199cf4051dedddelfMirai
2025-11-24 10:42:187496c6976b0e8438ea6f69e103f1af1e6d501a7fe26380914cbfc4010d6cf5b5elfMirai
2025-11-24 09:01:1708fe033056f2f363637df7eaa1395592cb81e9fe81cd47c0ebd4179dae842f31elfMirai