URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nicoslag.ru
Domain registrar:RU-CENTER -
Domain registration date:2024-06-19 00:16:25 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-08-31 09:03:02 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)
A record(s) observed :7

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 04:53:47 31.177.76.32Not listedAS48287 RU-CENTER- RUno
2025-06-20 04:53:47 31.177.80.32Not listedAS48287 RU-CENTER- RUno
2024-07-06 05:03:27 91.215.85.223SBL615768AS200593 PROSPERO-AS- RUno
2019-09-16 12:31:38 8.209.73.93Not listedAS45102 ALIBABA-CN-NET- DEno
2019-09-10 06:08:21 8.208.22.199Not listedAS45102 ALIBABA-CN-NET- GBno
2019-09-02 01:52:32 8.209.83.100Not listedAS45102 ALIBABA-CN-NET- DEno
2019-08-31 09:03:04 47.254.173.118Not listedAS45102 ALIBABA-CN-NET- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-06 05:40:35http://nicoslag.ru/ppx.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:38:22http://nicoslag.ru/mkv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:36:38http://nicoslag.ru/qwerty.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:34:57http://nicoslag.ru/telly.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:31:04http://nicoslag.ru/ghjk.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:26:35http://nicoslag.ru/pps.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:24:43http://nicoslag.ru/ghjkl.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:21:44http://nicoslag.ru/native.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:20:22http://nicoslag.ru/qwertyj1.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:18:21http://nicoslag.ru/payload.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:18:09http://nicoslag.ru/zxcvb.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:10:35http://nicoslag.ru/ali.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:10:03http://nicoslag.ru/zxcvb.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:09:13http://nicoslag.ru/net.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:08:01http://nicoslag.ru/asdf.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:03:28http://nicoslag.ru/zxcv.ps1Offlineopendir ps1 NDA0E
2019-08-31 09:03:04http://nicoslag.ru/asdfg.exeOfflineAZORult ext exe NetWire ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-08 13:53:4133682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:57:4533682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:56:3033682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:50:4933682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:35:1933682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-06 05:31:047ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:24:417ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:21:447ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:10:037ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:09:127ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2019-09-18 13:14:1017ffdbd35b562dbef82fcc2dc68b947ae85d5595a40b6ddd47035bfab18094b6exe  
2019-09-17 19:03:151f5085a36c7abbfe642aeab26a6212b9e8d67c8843cca64b309b2ea3005c011dexe  
2019-09-16 16:37:094e51d11f159ccd329ee72f1f4dc1caebc3fcdf0e45e7be1e9ecfb73e21affa80exe  
2019-09-14 16:42:46c942a025d5e6cdc5051f45a89c483c100a5fcfd01b7a43fccf62148c4a4eac8fexe  
2019-09-13 15:16:41896ff9878efd922fcfdff774a130373b84e90193fc483d48955b58886f367500exe NetWire
2019-09-12 14:23:2511a22234d884590d3fe678cc1844f9b1b3c9f71562d79af914ae0963b53ba81bexe  
2019-09-11 17:32:216e3360bcd7d3087b3b91e12e3d579791183c62a4a080448b44150a16a301d3aaexe NetWire
2019-09-10 18:00:20a1954b3233d9982d400046f616bbdf41f2e76aa11521cba382eb46de7a04a02cexe  
2019-09-09 18:09:2024d5d04a71dbe53240a63238bdd4b1437334ab3e680f41ba95e415669b184f43exe NetWire
2019-09-08 18:53:40e63cc3f8f8b05717f902094b11a415d96c9853d9638f6f978191711fee946167exe NetWire
2019-09-07 19:11:34de6d83f952fbcf923350a1431533862bfd089627406a9b0d349a6a8075648f02exe AZORult
2019-09-06 18:49:28ad666306537eb35ffdc18dc953d51988baa1312a1a5ca394014abf56d0b6802aexe  
2019-09-05 15:34:15be8b7677cd4daf54b6d50f60acdb0f11efa30129ff60b825b4f3c983d585120eexe  
2019-09-04 09:26:146b08e46f2376cfec1eff2c22e607c4ff60e34442482c7a9469cb3c381fe561fdexe NetWire
2019-09-03 08:48:19f13769a0e1aaeb75f886719a5d4a22b0d4697df05701b935679eae92df1234e6exe  
2019-09-02 09:17:14300109be347c94f02dbc67208e9088370ae2daf37a5b7317fc9a19bc8f410fb8exe  
2019-09-01 10:03:199b412eff3b3fd04218366bfecc33de87707f4a709e40fec04b08751f71463c76exe  
2019-08-31 14:13:090373dfda4d4e96c6a38a8c68c0b738939cbb39ab0549d1fbea10539ec1091c91exe  
2019-08-31 09:03:03633cd45092ef3172fda8e5a821fcdd39ba6e81e752f3665d97e91190b228353eexe