URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pay.aqiu6.com
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2018-10-11 06:26:02 UTC
Total malware sites :2
Online malware sites :1 (50%)
Offline Malware sites :1 (50%)
Newest active malware site :2018-10-11 06:26:14 UTC
Oldest active malware site :2018-10-11 06:26:14 UTC (Age: 7 years, 8 months, 25 days, 21 hours, 3 minutes)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-30 12:11:33 116.62.166.48SBL692514AS37963 ALIBABA-CN-NET- CNyes
2020-04-21 08:00:14 121.199.250.220Not listedAS37963 ALIBABA-CN-NET- CNno
2020-04-17 02:51:45 121.199.250.10Not listedAS37963 ALIBABA-CN-NET- CNno
2018-10-11 06:26:14 121.199.250.203Not listedAS37963 ALIBABA-CN-NET- CNno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2018-10-11 10:29:27http://pay.aqiu6.com/download/WeiPay.exeOfflineexe zbetcheckin
2018-10-11 06:26:14http://pay.aqiu6.com/autoup/Client/AQClient.exeOnlineexe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-06 23:32:5830fa4904cc2616a1b81f5baa3accfabc8d6a4f857cd69922ce00788c2927002fexe  
2020-04-15 02:38:100afc026d81a209d2b048c70e87eb7d4f0fdc84024565d44d67b0b4a235b3f454exe  
2020-01-21 14:52:586d10276547d261878cfd679ca39743101acb4fad711e6b0445a52c617a0b2950exe  
2019-01-28 17:28:49bca9ff4da9c78895a174ca414d4e6c76178cd9e020730a0352734883153e7733exe  
2019-01-25 20:34:34c20f27d9350cf01cf5fc0ee50d79fe4bf73e99882cf67d07fd35890cc4c45264exe  
2019-01-12 13:53:4618e59bd9398c8816d4949168287e5da287996ff0106e142df157acea12b13219exe