URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: oniondq7shlx1001.cyou
Domain registrar:REG.RU -
Domain registration date:2021-12-05 20:32:36 UTC
Abuse complaint sent to registrar: Yes (2021-12-15 17:37:01 UTC to abuse{at}reg[dot]ru)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2021-12-15 17:31:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-15 17:31:09 31.31.196.218server240.hosting.reg.ruNot listedAS197695 AS-REGRU- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-15 17:32:11http://oniondq7shlx1001.cyou/cpwsfmvg.exeOffline32 exe zbetcheckin
2021-12-15 17:31:09http://oniondq7shlx1001.cyou/miexciuz.exeOfflineCoinMiner exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-17 12:32:022e8a145ffb3a383cea9921fe6b9d51a1b552ddd1686ed04adc463306eacf105cexe  
2021-12-17 04:42:2634ff0fbef3847b8e1312aaa4d29f1d91fbf172a23071243636b844929476d140exe  
2021-12-17 04:27:16df0bd3c0ed94d6f87b32574f5d6cfbbeade15a2aa59a4d60f9bf2ed70008a470exe  
2021-12-16 19:22:0931d6605b949dcdc84f3e423ca7a1c6f465a26f2bced375c3b697bc116b9eb3f1exe  
2021-12-15 17:32:09925b7b38868675725656b93e6d7349048a3702fc13b8fd62b305155e332b8980exe 
2021-12-15 17:31:09d29acdeb134477223baaf3b97aef34f5ff2b5832567718025bdac30421ac7ad7exeCoinMiner