URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cad.659t.cn
Domain registrar:Alibaba -
Domain registration date:2023-09-19 00:17:13 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-03-11 08:44:11 UTC
Total malware sites :1
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-11 08:44:15 121.204.249.146Not listedAS133776 CHINATELECOM-Fujian-Quanzhou-IDC1- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-11 08:44:15https://cad.659t.cn/static/setup/autocad_v1.4.exeOffline juroots

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-04 07:42:56b037c93b7b8dc1a0dd521136f567560b1286ed8880d11b7d2790bfa1699bdcffexe  
2026-04-02 04:47:13639de7d92dea86399dc6117af21d8d8d8eade60bbdd85350b838f8c4c4104cc1exe  
2026-03-25 16:49:05ae33cea2ed4bded6958ddde4b39d2cc23e22ce8701aba027b9867d01455d51f6exe  
2026-03-11 08:53:0517d2b3fb0c1942c43588d26ba9aecd6f6a9a549f86a8bb4120865cfbd9caf137exe