URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cdn.riowt.top
Domain registrar: n/a
Domain registration date:2020-03-15 18:06:28 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-11-28 20:16:08 UTC
Total malware sites :1
A record(s) observed :60

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-14 18:31:45 104.21.5.141Not listedAS13335 CLOUDFLARENETn/ayes
2025-10-14 18:31:45 172.67.154.165Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-28 02:33:50 38.14.223.218Not listedAS400619 AROSS-AS- USno
2023-06-10 14:01:01 156.226.123.39Not listedAS135097 MYCLOUD-AS-AP- HKno
2023-06-01 07:26:32 142.4.119.253Not listedAS54600 PEG-SV- USno
2022-04-16 23:04:41 43.241.18.115Not listedAS134771 CHINATELECOM-ZHEJIANG-WENZHOU-IDC- CNno
2022-03-04 16:28:54 94.23.253.55Not listedAS16276 OVH- FRno
2021-11-30 18:25:17 150.138.219.113Not listedAS58540 CHINATELECOM-SHANDONG-JINAN-IDC- CNno
2022-01-24 15:52:25 113.106.101.124Not listedAS4134 CHINANET-BACKBONE- CNno
2022-01-24 15:35:54 113.106.101.120Not listedAS4134 CHINANET-BACKBONE- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-11-28 20:17:13http://cdn.riowt.top/Update.exeOfflineexe Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-02 07:39:5785e15b3eb8e24cb121a4da1a853fd56098881c49ad05a2d60047c241fd76302bexe  
2021-12-02 04:31:448717572cb2b24423c781f13c1cd81b0333403977da22d5cff9f434f45005cb37exe  
2021-12-02 01:38:23371bd341beba563c7efca284d91abb0acdb6b2ed2e41ad2822ef2f79bc6cac79exe  
2021-11-28 20:28:577c28b994aeb3a85e37225cc20bae2232f97e23f115c2a409da31f353140c631eexe