URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: partaususd.ru
Domain registrar:RU-CENTER -
Domain registration date:2024-06-19 00:16:25 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-08-31 08:42:02 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 01:45:28 31.177.76.32Not listedAS48287 RU-CENTER- RUno
2025-06-20 01:45:28 31.177.80.32Not listedAS48287 RU-CENTER- RUno
2024-07-06 05:03:44 91.215.85.223SBL615768AS200593 PROSPERO-AS- RUno
2019-09-29 08:49:34 129.226.61.210Not listedAS132203 TENCENT-NET-AP-CN- HKno
2019-09-29 07:50:25 161.117.202.159Not listedAS45102 ALIBABA-CN-NET- SGno
2019-09-27 06:51:16 8.208.76.142Not listedAS45102 ALIBABA-CN-NET- GBno
2019-09-25 04:38:15 47.90.242.80Not listedAS45102 ALIBABA-CN-NET- USno
2019-09-23 07:51:56 47.254.192.98Not listedAS45102 ALIBABA-CN-NET- MYno
2019-09-19 10:21:22 47.252.11.188Not listedAS45102 ALIBABA-CN-NET- USno
2019-09-16 12:31:35 8.209.73.93Not listedAS45102 ALIBABA-CN-NET- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-06 05:42:09http://partaususd.ru/pps.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:40:17http://partaususd.ru/ghjk.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:34:31http://partaususd.ru/asdf.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:32:39http://partaususd.ru/mkv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:31:12http://partaususd.ru/payload.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:30:50http://partaususd.ru/ali.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:27:54http://partaususd.ru/zxcv.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:26:04http://partaususd.ru/telly.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:25:17http://partaususd.ru/net.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:22:15http://partaususd.ru/zxcvb.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:17:47http://partaususd.ru/ppx.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:16:37http://partaususd.ru/qwerty.ps1Offlineopendir ps1 NDA0E
2024-07-06 05:13:34http://partaususd.ru/ghjkl.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:13:15http://partaususd.ru/native.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:12:03http://partaususd.ru/asdfg.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:06:44http://partaususd.ru/zxcvb.exeOfflineexe opendir Rhadamanthys NDA0E
2024-07-06 05:03:45http://partaususd.ru/qwertyj1.ps1Offlineopendir ps1 NDA0E
2019-08-31 08:42:02http://partaususd.ru/asdf.EXEOfflineAZORult ext exe NetWire ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-08 10:41:1233682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:19:0333682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:07:4933682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 10:02:2533682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:43:5833682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-08 09:21:3733682e861b76b0ae22b7361f5b59bb7e69b95e69480156714f01e7044408b546exeRhadamanthys
2024-07-06 05:40:177ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:25:167ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:13:347ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:13:157ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:12:027ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2024-07-06 05:06:437ccfae8644c3bc7439b88f2dc0de06bb5082de09b0bf5e143de17487ff252224exe Rhadamanthys
2019-10-07 18:27:55c323b1c61fce054bc6b51f5a0b018e9e75163398a430c77829053c874e99070eexe NetWire
2019-10-06 15:35:32d5074ebcb09f4cfd113c54f2001c211faf612763de97b064d935af12f9694038exe NetWire
2019-10-05 17:38:171a8905a7540970f2217360a38d9c02231bd8a3a7dd04ce0d5592d8f74f9e69bcexe  
2019-10-04 12:54:149491b6245a6dcb2bafb479f37f5b152e938951e876ae64165d6be864a4ddeec4exe  
2019-10-03 14:55:5887d85f037a335c6ae7e2c6f5126292d589e7f435bf498ccb7ff6d0eb3e2891e0exe NetWire
2019-10-02 13:05:3225ea02d374261d3bfa43c9c9e870b6369416977380c57c31e182c90cf10d27cbexe NetWire
2019-10-01 11:59:3859a0db1a1962d4ac19733cb6b09db9c3a466af9f8784c23dcf9c9fb2e56764e3exe NetWire
2019-09-30 15:44:30e91a6a2cf1bbd90ce801051ad2c3cdb8b3d7a30e3156eb4d4040ef461c475557exe  
2019-09-29 15:17:25dfcde8a83cd63668a06e61c8662fd7a5616620b26e73f3066c43ff1198f173bfexe AZORult
2019-09-28 18:17:555ef3e6cd6a36e404358d05f2466e181216865db67d26e46a59925ba422ab8a99exe NetWire
2019-09-27 14:58:05fba0aa7a56e03b0fcdbe81e75bb30f4cbc9c0e2793ceca25fdd76c9195d44115exe NetWire
2019-09-26 15:06:276ecc9c565124a0a10d48e9a162bc3b017f102d7bd6223d2cea727808335acaa7exe NetWire
2019-09-25 14:14:34a2991511c140466a2e43899f3a0f4f75a3578a80b2959fd05048b47cfd359fe5exe NetWire
2019-09-24 15:46:2521b295fe8632d5e1a7b06e7f7b5384b5eb4403f3d4887f1740e0fb7773f3c32dexe NetWire
2019-09-23 14:11:128c2607698ca26d631a02e9f59d6819986b860d76a7f9e178f20d8cac7b4fc1daexe NetWire
2019-09-22 14:44:120ce1ee263c3d1ecd89fd1a912dab98764d03fc34f1d887905948a72cd5f1b336exe  
2019-09-21 12:19:081b3eed52e35e2068200ccc21984db3dd5ca23eea63544194090715ac9a981bb5exe NetWire
2019-09-20 15:01:21759b51159d85f303d969edaa08203853feb307e9f5d86b69e1efa567dffeeb13exe NetWire
2019-09-19 15:38:2551ef54af1060bc0e421dc2c38050efed96d7c3feb14c0dfa1b35002ac076241fexe NetWire
2019-09-18 13:14:14a36c7846f0e27dee5a53d53ff24132eb81c5e1f8ad437bc8685374118183e636exe NetWire
2019-09-17 19:03:2250197fb4a7760a5e73a30457618f88543670607e2c8bf2fad1a10f41fff50544exe NetWire
2019-09-16 16:37:17ca45ecfadb7558e2fd1971d274c0d707de272cc97b4a383e21929814f650b10eexe NetWire
2019-09-14 16:42:51d02618502b33bdb86a73cd33d2f4b8144620fcb87fdffefbd2c107aaa2f76353exe  
2019-09-13 15:16:44e4d258b78adbe54bf2bf0e4a9f7192c8ecc3813888f760560e28a7d44e59797eexe AZORult
2019-09-12 14:23:4578bb9983865b827d71d93c403facf3328d2a440ccf3998eac7a949862eeb426dexe NetWire
2019-09-11 17:32:24dbf842f60b42c9adaddabd1088d01965cf06dc8df6744197b8ed4acdb56502ebexe AZORult
2019-09-10 18:00:321f0b7d79bb14a7e6bb8d939e6a3f38ddbd3ef2c0446b0b69369eb39a52c2cf9dexe  
2019-09-09 18:09:23c44080672d66b21a6a11d56b4ba7b38f44fc9fd366d8a3a4e40c374592a678f0exe  
2019-09-09 10:31:204ceb34780302570bf05dfcf5afda959a78f712ef44c4dbd611b009cbef983fb2exe