URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name). This page shows all malware URLs that are associated with the host down.ctosus.ru.

Database Entry

Spamhaus DBL:Abused domain (malware)
Firstseen:2018-11-04 17:47:01 UTC

IP addresses

The table below shows all IP address obsered for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones).

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2019-06-01 01:45:3045.12.204.223Not listedAS9009 M247yes
2018-11-04 17:47:0323.94.62.12723-94-62-127-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING - ColoCrossing- USno

Malware URLs

The table below shows all malware URLs that are associated with this particulare host.

Dateadded (UTC)URLStatusTagsGSBReporter
2019-04-25 14:33:04http://down.ctosus.ru/wkinstall.exeOnlineCoinMiner exe Clean@zbetcheckin
2018-11-04 20:21:11http://down.ctosus.ru/ctos002.jpgOnlineClean@de_aviation
2018-11-04 17:47:03http://down.ctosus.ru/hh.exeOnlineexe Clean@zbetcheckin