URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cheapd.link
Domain registrar:Namecheap -
Domain registration date:2022-03-14 19:54:21 UTC
Abuse complaint sent to registrar: Yes (2022-03-24 18:56:02 UTC to abuse{at}namecheap[dot]com)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-24 18:51:04 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-25 07:13:53 34.65.129.7676.129.65.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- CHno
2022-03-25 06:07:13 185.38.84.29info.xuweidong.clubNot listedAS12616 HOSTING-MSK- RUno
2022-03-24 18:51:06 91.224.23.203Not listedAS216087 SQB-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-24 18:51:06http://cheapd.link/CALC1.exeOfflineArkeiStealer ext exe benkow_

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-25 15:31:52c4df33a185795d197ca23e599e8635827ee82800f0736a95e2466e00226cfd7eexe  
2022-03-25 15:04:3588d3c2e14058fe791a3495bef77ce1436ce605c5b63c314944333f20a6f7554fexe  
2022-03-25 14:14:196f8d8ef94648300b0ff28111cdb4c1c171738ec06571601d5e9c92a73e4342f2exe  
2022-03-25 13:45:5812af55a1b76bc59d96116a5f1bc55d3c4ff466f27d3ef2dfce59ff7a14c7e408exe  
2022-03-25 13:25:12cca6bea3acf986babf24513880bd4b9f6983d9cd646932140b53483c19756709exe  
2022-03-25 12:08:47c8ad2381228ece7fd82d2fce6cbbf5bfc07167758cb6c55cfd60b3ad6e9005eaexe  
2022-03-25 10:32:105b65428cd0d750804538847380ce823fe1975121db7250bdb0113194744d0c80exe  
2022-03-25 08:49:0439505867796eee9423b7b258362e09892327a7177eb7651f0ded6f04bb85245fexe  
2022-03-25 08:27:56ff5f03a8c342ea0fc07bedd4affb43af4744a1df3dc5ee3f17a309c78ea6eaaeexe  
2022-03-25 07:32:119918c9e5a1d65658e8cd25fc29fb1566d9d7cac83cdb9484ecb3548a46ce3b0aexe  
2022-03-25 07:13:51832c70671a8a670679ada1fc611856a1fb0e756ff819cff7c5a3f23e2fa2dc17exe  
2022-03-25 05:04:33d7da06ee227da2c3c5fa08cdb674b9b430b6fd84f45bd0bc6e324dad0278888bexe  
2022-03-25 04:40:206b560318567d285742c709cfb82b3571c51b15d01d652a8527cb49505e3fad56exe  
2022-03-25 03:20:28ba3fc73699cf76055d2ff71fff603ae83733d17c9c0822ec12d154bb49c88d7bexe  
2022-03-25 02:17:23b21920cc211fa6201f406839d62f10dfc5c81db358960c008a97d8749b31f235exe  
2022-03-25 01:10:35f62d103f9f80c614b1b9fdb823751419146179d30af040eba7f67744fe3fc546exe  
2022-03-25 00:09:05c1d5d69eb1ff280308e0f581e476322cac9b64e745886ad356fd05e843cff342exe  
2022-03-24 22:47:08f116304222910da33ea1591718b51f4def44136626809130ecfe10d82c9c533bexe  
2022-03-24 21:40:58a602b864545539a7981c58a0684e59bd847b9da0e0f5048e03639a419a57e5b9exe  
2022-03-24 21:08:38267a45c8cdb5296035bcb6433ed981afe34934b30b82c18d5780aeece972b385exe  
2022-03-24 20:55:332a13b3b4e815d3856fb26b89dbcfb06a5b025db7f4c0e398ccdbc4477e3d2f58exeArkeiStealer
2022-03-24 19:04:14573f167f1bdc3b46aad784dd1279d5460857837991fcc1769920c0435a961ef8exeArkeiStealer
2022-03-24 18:51:0511973b874396eb86766823cf182a40f8ae9e6011e822b64c21e5b13a93922293exe