URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: citycapproperty.ru
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-01-11 15:33:15 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :72

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-09 08:05:49 92.53.116.105timeweb.ruNot listedAS9123 TimeWeb-AS- RUno
2021-06-14 15:02:21 35.185.52.235235.52.185.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-06-10 19:06:44 35.242.217.99.217.242.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- DEno
2021-06-03 16:39:12 35.203.61.165165.61.203.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- CAno
2021-05-31 16:29:02 34.95.133.146146.133.95.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- BRno
2021-05-11 01:20:32 35.247.240.225225.240.247.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- BRno
2021-05-10 07:22:25 34.106.167.2525.167.106.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-05-09 18:58:50 35.247.109.1111.109.247.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USno
2021-04-30 15:17:45 35.247.216.128128.216.247.35.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- BRno
2021-04-28 11:12:02 65.21.146.189static.189.146.21.65.clients.your-server.deNot listedAS24940 HETZNER-AS- FIno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-02 13:15:09http://citycapproperty.ru/zedmania/name.exeOfflineexe QuasarRAT ext zbetcheckin
2021-06-02 12:03:12http://citycapproperty.ru/mailservice/nmode.exeOfflinedofoil ext exe Smoke Loader ext abuse_ch
2021-01-05 08:05:06http://citycapproperty.ru/localmod/nmode.exeOfflinedofoil ext exe Smoke Loader ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-06-02 13:15:092fb3d54a36d316831e170d9827dd8b7086875d24b92b1dda5b140151e75386f0exe QuasarRAT
2021-06-02 12:03:112818aa3050eba2fb576a881e61ed655ad29d99e45dc9e19afaeae18cc035f671exe Smoke Loader
2021-04-29 10:47:185f31050b511cf181abfa18b04cdc3a4152afc18c34b4ffc1087496144ac56a7cexe Smoke Loader
2021-04-28 09:25:47d73e37b3ed710e4128e3c76e2f0fd61dbb2fdcddfd8cfa51ffe244fa19433bb2exeSmoke Loader
2021-04-22 05:32:19f1018c92a0545fa449dff41150230eceae4bc8e4652a214c9efde2abb10bc71dexeSmoke Loader
2021-04-20 05:26:505d82b4f16469d125e3615431b1ccdbbf2decc388e1e3b417d2c0e12e0cca78f6exeSmoke Loader
2021-04-19 05:27:5660922af94a3c7adf6d040dc1bd4d465983a38bd2410c050bef27deda8ce2002fexeSmoke Loader
2021-04-19 03:29:0716e3380b11358d44b7e1e4cc6ee7ce80ef204321b731a550527375388703163dexeSmoke Loader
2021-04-19 00:38:245fb0f6085605274b85114c9bfe761e13e481abcaebe2adfb612e34542346cb4bexe  
2021-04-12 03:34:05643bafce44fec576424c48dbef72072a1d27d33b60e25585d39bdbcffdca22e8exeSmoke Loader
2021-04-02 04:21:52859abafdd459914e32b32dd036ec9f9ca9ecb60a293b4da6bcc08ebec22e9781exe Smoke Loader
2021-04-02 03:46:190f32500a74e76831740141dfc69676b97a72f9f66da30dfa3aa8648b836373cfexeSmoke Loader
2021-04-01 05:13:33b5a1d98b73f59a3df3121b11001e26b11c5555e7ac80ac2b2d42f832db7a4a0cexe Smoke Loader
2021-04-01 03:47:523e034663b9f2c2463c68e677fd1bbc7643882e5d6cefc05910d9ad1230f89c8cexe Smoke Loader
2021-03-23 05:52:1587cd4125176db45ac6d32ff5979fcaf1d29eeac328323f545326bf0d63400967exeSmoke Loader
2021-03-23 04:18:0003d92e1238fcdb64e522bad8b8c152d85de2036a6aedf152e5c3bf24d3017d07exeSmoke Loader
2021-03-19 11:31:38961b36bb78d27b3432fae08e5c4272fe295b5e24e832c6f6bf1ec3cf87057dabexe 
2021-02-18 06:54:50c684906ca32b3dd720ecc86aa54ca56a69f8300e112bd3af5f54d569e9e5ba27exeSmoke Loader
2021-02-18 05:45:20229c6f4db65ef671df9f2af39af518ed9dde8d5401c172190a936565cf2772f2exeSmoke Loader
2021-02-18 05:02:14b2accff6cdcb8f4b5cbf2e493a8474f9e444a12be5f46d54a925bbe4a43a0703exeSmoke Loader
2021-02-16 13:53:22a60a583165e55f8a569cf4942d7bfb9622ab349aa34aec48705f72cbf3b2e45fexeSmoke Loader
2021-01-27 05:18:0674bbc2a055be8f2717fa06e764b100d02f9a1d9c2a026d281fbbbbb47b655199exeSmoke Loader
2021-01-26 06:49:41ab9e78f844176f90e2815978b083362683d6080da73034a019de13489aa125e7exeSmoke Loader
2021-01-26 05:10:413a80488a011783f820406817bb351b4ba703110ed51a254eb678306c21507877exeSmoke Loader
2021-01-21 07:00:34c65ea9eee506b0a71170d4e3778d3ccadda12f67217e89e3b93db61890ab548dexeSmoke Loader
2021-01-21 06:20:147872b734ebb4d0f224a04a88059432081d8908dd79e7d46ea8b4ba7b31ebfeb7exeSmoke Loader
2021-01-21 05:40:5392fa3d23707a84257ef148d1afd2839ccc2ae0d14863216fd1652ced7cc685a3exeSmoke Loader
2021-01-21 02:08:2275973aa6b9ede942a1a0ec330218c3a2bee3d2de638482592f1f60976898ca81exeSmoke Loader
2021-01-14 05:24:510b9555e73d90f0ff2506c001b5fed2e986f74e8e988cc1a4a8dc0e1dd377113bexeSmoke Loader
2021-01-11 06:10:14d4e87e3eb3e3a5e08db5a708bd95fedac322088446c87ba37f0aeca529a928ccexeSmoke Loader
2021-01-11 04:55:43fcb987579a7161622043553819e18e3dee2e50ea149e5b7438ac614548278405exeSmoke Loader
2021-01-06 06:06:406aceacb6120a5a270ad7906dcedc5fcf3059323b6c2f52e5b3eb83a91630ed8fexeSmoke Loader
2021-01-06 05:09:3073bd0ef4821814fb351197b6967d35274f9f33de491faca434aeeb63a51072bbexeSmoke Loader
2021-01-05 08:05:06824bb4f0ae66624021f9428d253f15f751653dfb059f9a2db4a6551b0a168a0bexeSmoke Loader