URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: paipaisdvzxc.ru
Domain registrar:RU-CENTER -
Domain registration date:2024-06-19 00:16:35 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-11-23 10:53:02 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)
A record(s) observed :15

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 06:48:22 31.177.76.32Not listedAS48287 RU-CENTER- RUno
2025-06-20 06:48:22 31.177.80.32Not listedAS48287 RU-CENTER- RUno
2024-07-06 05:03:06 91.215.85.223SBL615768AS200593 PROSPERO-AS- RUno
2019-12-18 13:49:00 161.117.82.197Not listedAS45102 ALIBABA-CN-NET- SGno
2019-12-16 10:23:19 161.117.231.76Not listedAS45102 ALIBABA-CN-NET- SGno
2019-12-13 10:53:53 8.209.73.221Not listedAS45102 ALIBABA-CN-NET- DEno
2019-12-12 08:27:07 8.208.19.69Not listedAS45102 ALIBABA-CN-NET- GBno
2019-12-11 12:07:02 161.117.229.190Not listedAS45102 ALIBABA-CN-NET- SGno
2019-12-10 10:37:37 8.208.26.255Not listedAS45102 ALIBABA-CN-NET- GBno
2019-12-09 08:14:48 8.208.26.10Not listedAS45102 ALIBABA-CN-NET- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-06 05:40:07http://paipaisdvzxc.ru/ppx.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:39:38http://paipaisdvzxc.ru/native.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:34:19http://paipaisdvzxc.ru/qwertyj1.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:32:17http://paipaisdvzxc.ru/telly.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:25:48http://paipaisdvzxc.ru/ghjk.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:23:51http://paipaisdvzxc.ru/qwerty.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:21:24http://paipaisdvzxc.ru/ghjkl.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:15:45http://paipaisdvzxc.ru/net.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:15:05http://paipaisdvzxc.ru/zxcvb.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:11:34http://paipaisdvzxc.ru/zxcvb.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:09:26http://paipaisdvzxc.ru/mkv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:09:11http://paipaisdvzxc.ru/asdf.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:07:53http://paipaisdvzxc.ru/zxcv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:05:55http://paipaisdvzxc.ru/ali.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:04:58http://paipaisdvzxc.ru/payload.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:03:06http://paipaisdvzxc.ru/pps.ps1Offlineopendir ps1 NDA0E
2019-11-23 10:53:05http://paipaisdvzxc.ru/asdfg.exeOfflineAZORult ext exe NetWire ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-08 10:16:3533682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:13:4433682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:03:4733682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:48:3133682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:22:5533682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-06 05:39:387ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:25:467ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:21:237ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:15:437ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:11:337ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2019-12-26 12:40:048f3572f1eb7e013e9eb14de088e159d44f139df51b6d78b0eb81128e010b3fb0exe AZORult
2019-12-21 16:52:213032c581091576e78447af575a5e14394f45f7599317f5fc138b8ff80eba60d9exe NetWire
2019-12-20 08:09:42075c18102f7389dab6173a503b42c997ff27e66e71b8fc468b25e359e9963e77exe  
2019-12-18 12:45:32fb0dff8c7e3049d7038a7e0472c75f24f117f0940a75655bd5f5a871c18e830bexe AZORult
2019-12-17 14:52:31b5ef21302dbd344198a70b1b3e8b05ca28eaa328cfdaea04be4f1ea7aef8de48exe NetWire
2019-12-14 11:42:46816d77d5f9b0331b4762edb4ff7536a7fdc86f4437eabd2cc8bd24a240ecc7e9exe AZORult
2019-12-12 14:16:0506a3c5b5f348b42acd769b18376f7f11fdee4ac07ecb4dcec0fcebda0150d456exe AZORult
2019-12-11 16:09:276b5d88b2123163650379a35547381b7fda144110bf57828daf70fe33ec497191exe  
2019-12-09 14:11:55dae5e0036fe04446a78cce3e5bf8d884751ed8d68fa8c825034fa449dc40f4c5exe  
2019-12-08 20:05:10167d857799fec4d5aba8bb72c0999cfdfb2364a6306daf03f7e52ef630e3baefexe NetWire
2019-12-07 11:26:4502e83a34d40cdc813b0baf6f47c0790fd55d67032c60ad6bb137aa8e64f0d26dexe AZORult
2019-12-06 12:10:0679ddc90fe9d6791bdad50e078d3d5193375f2299a76d07b841e4e0aca6efd4d2exe  
2019-12-05 17:56:0363535df75734734eca7d2c1ffbb16c2ac7f96e7b598b1ddb1ccc266dd439a03aexe  
2019-12-05 04:56:30c9c963c27a5b429cbb7fda91863a1d3349ed6d8fad24c89e5360c458e9ed6e99exe NetWire
2019-11-28 10:38:450bf839a2aaedcb3a428453db89393c579bc4771c4a65753ca64828621189172fexe AZORult
2019-11-28 09:41:124f9256a888e49a54efae7958421a087111f1402679e61ef92a30223722173e78exe  
2019-11-27 13:23:399f9ad6c8f98a3af6f55274bbb63cd66119a69a9fd89dc146be47f3d63761eb39exe AZORult
2019-11-26 14:06:29174cd7c62deae72cd44b810784557fb01bfdeeb9f6f537c6639d7307d1387a36exe  
2019-11-25 15:11:211d8fe1ee69caa87ae8b987a3f6c443916e65a8e413820584fbdd4140365bc4dcexe  
2019-11-24 16:10:2036716bff0c5f454b406bf226115b01206d74f1cf7386b8dbee75f318707a5dddexe  
2019-11-23 17:24:1670fcab2db15a660e022aa44d02c0b8bf2322cebf47eb92f84c5a985a889a9c48exe NetWire
2019-11-23 10:53:0422318fbb216a4774fa8c9f2e1c41b3ef1d8168bdb39c1bd9193a24742143fda1exe NetWire