URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gekata.ru
Domain registrar:domenus.ru -
Domain registration date:2021-10-05 14:05:21 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-19 08:34:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-30 04:51:50 31.31.205.163ns1.domainparking.int.reg.ruNot listedAS197695 AS-REGRU- RUyes
2022-07-10 10:19:27 45.130.41.25Not listedAS198610 BEGET-AS- RUno
2022-04-26 05:06:58 91.106.207.25m2.golf.beget.comNot listedAS198610 BEGET-AS- RUno
2022-01-19 08:34:04 31.28.24.126c16w.hoster.ruNot listedAS29076 CITYTELECOM-AS- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-19 08:34:04http://gekata.ru/designthemel/0849363886965837/...Offlinedoc emotet ext epoch5 heodo ext Cryptolaemus1
2022-01-19 08:34:04http://gekata.ru/designthemel/0849363886965837/Offlineemotet ext epoch5 redir-doc xls Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-19 14:00:06f402293949516548cf2d981894ff8b70d867c113c15c0c5cae972a0139ffde08xlsm Heodo
2022-01-19 13:43:31f9701b36e31d43185b01940b566bbf5db0dd4b67a324f31ed892479af4bc865axlsm Heodo
2022-01-19 13:32:187b0c31e2bebb43c3b611177b359cdc3c7ee1ec93e44b50eef4d22fcdbe208e99xlsm Heodo
2022-01-19 12:43:3012096d0db788662f717f1757f957629e692fc998bb1f86844980fc0b313f17aexlsmHeodo
2022-01-19 12:27:1186126169aa0ea824a141217cdfb2b6796f7c513fe9e21559cfd3ee05f9e32e28xlsm Heodo
2022-01-19 12:18:4534fbb165d1df32c51b45c90739709ffd44a7b582b0d0b508605d698a5e8ce52axlsm Heodo
2022-01-19 12:03:22e98d6968eccf3af8dac1aafeb1eff78a52251e86932c3342832fbe24ba7bb0ddxlsm Heodo
2022-01-19 11:43:588cc57e5d6c185250f46cc0076c809b750f1f60a193e80bcc8c6701621b785d62xlsm Heodo
2022-01-19 11:37:41c825272b631c355875fc48e3a914397611e5c9ba65f13ceaa4cf9fd7f6d92a17xlsm Heodo
2022-01-19 11:24:4314e064f7f62bcfb8f520797593104d69cef2cbb090ac4f36b871ced2daab192bxlsm Heodo
2022-01-19 11:00:30aca67468ced86d88c980d851092607e06405b3109230404fb7c51c6c916f389bxlsm Heodo
2022-01-19 10:49:58e12ae7f5d840134b7d6b1bbd7c5753ca44b4c70f8e18d1b21b8c9377d5a4253dxlsm Heodo
2022-01-19 10:38:530bd208787cd1e8f9a0fa2c96534f1785b655ad56534abac7b4ce3d1f2f2f062cxlsm Heodo
2022-01-19 10:19:43b80bcf2ea57e2d87665f00cd07f6df0049170b65b541621ce3ed45a589d20980xlsm Heodo
2022-01-19 10:08:41bedfbe47fbde08c3b2471c10061982611d471e5feae913cb7f91e63003a1a5ccxlsm Heodo
2022-01-19 09:53:30a675b7d974851232b65d25e7fcd87697f9cbbd9a6bac4d21b14a1e249015d321xlsm Heodo
2022-01-19 09:28:54fb52c8cd5527da88fe38a96ea9bb45772d3a2e6e317d1e6249a301ae8ef05ed5xlsm Heodo
2022-01-19 09:18:25d7bb3e935a6b066a86cf79ee17a9368b1d461a76a92f9478b694f2c0275beaf7xlsm Heodo
2022-01-19 09:03:49ff21e0d799e7757351192a77594d12cce77faf6ebc669816ad4bc37ded38d952xlsm Heodo
2022-01-19 08:46:23fbc47a25d026a1d3aabf04c65781142ef8d17ce0071e44f5925e33a2e3f715dexlsm Heodo
2022-01-19 08:34:04e48f46cd60cb0b369d14352daf83f4a07f78332ff849bf8acf3729fcfd19cd47xlsm Heodo
2022-01-19 08:34:043b5298a406eb45eb1fee1b76cd8c4014d18fa7112c81ed7e5071c4578fe1ebe1html