URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: artemdukshiola.com
Domain registrar:Alibaba -
Domain registration date:2021-10-04 18:07:08 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-02-17 12:39:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :23

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-10-05 20:19:14 47.91.170.222Not listedAS45102 ALIBABA-CN-NET- HKno
2022-08-03 23:54:44 20.25.104.87Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USno
2022-07-19 19:57:09 20.125.140.90Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- USno
2022-07-12 10:23:58 20.68.120.252Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- GBno
2022-06-29 23:54:31 20.70.187.135Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- AUno
2022-06-24 22:38:33 18.191.18.23ec2-18-191-18-23.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-23 15:59:44 35.89.155.158ec2-35-89-155-158.us-west-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-22 20:15:12 18.221.6.126ec2-18-221-6-126.us-east-2.compute.amazonaws.comNot listedAS16509 AMAZON-02- USno
2022-06-19 05:08:36 45.156.22.8Not listedAS56971 AS56971- FIno
2022-06-10 21:10:35 194.53.109.29Not listedAS136787 PACKETHUBSA-AS-AP- CAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-02-17 13:32:04http://artemdukshiola.com/nk/nk.exeOffline32 exe Formbook ext zbetcheckin
2022-02-17 12:39:06http://artemdukshiola.com/nick/nick.exeOffline23.105.131.161 NanoCore ext c_APT_ure

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-02-17 13:32:047b852a4852c80c7ee93aa336b719ab67613776b5bc24f9e0d881b978662522f4exeFormbook
2022-02-17 12:39:0502d44242883b8345b668b6fd15fec4d9d2b44bd54f34a28290afa491395f67f2exeNanoCore