URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: psm-ir.com
Domain registrar:OnlineNIC -
Domain registration date:2005-06-01 13:39:21 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-08-23 18:06:03 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)
A record(s) observed :26

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-05 09:24:45 172.65.190.172Not listedAS13335 CLOUDFLARENETn/ayes
2025-05-23 07:53:01 107.163.253.53Not listedAS18978 ENZUINC-US- USno
2025-04-27 11:08:08 107.163.191.16Not listedAS132839 POWERLINE-AS-AP- USno
2022-12-08 22:34:13 134.119.176.25Not listedAS29066 VELIANET-AS- FRno
2023-06-05 20:49:46 134.119.176.30Not listedAS29066 VELIANET-AS- FRno
2023-06-05 16:48:55 134.119.176.28Not listedAS29066 VELIANET-AS- FRno
2023-06-06 00:53:55 134.119.176.23Not listedAS29066 VELIANET-AS- FRno
2023-06-19 17:11:50 192.155.108.156Not listedAS29066 VELIANET-AS- USno
2023-06-16 21:35:54 192.155.108.152Not listedAS29066 VELIANET-AS- USno
2023-06-07 00:28:08 134.119.176.26Not listedAS29066 VELIANET-AS- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-08-23 20:58:05http://psm-ir.com/powers/pope.exeOfflineRedLineStealer ext zbetcheckin
2021-08-23 20:58:05http://psm-ir.com/powers/yg.exeOfflineRedLineStealer ext zbetcheckin
2021-08-23 20:54:07http://psm-ir.com/powers/deck.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 20:54:05http://psm-ir.com/powers/joboy.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 20:54:05http://psm-ir.com/powers/omass.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 20:50:04http://psm-ir.com/powers/pals.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 20:49:04http://psm-ir.com/powers/musik.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 20:41:07http://psm-ir.com/powers/jojo.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-23 18:07:10http://psm-ir.com/gemni/nd.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:09http://psm-ir.com/gemni/sy.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:05http://psm-ir.com/gemni/mn.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:04http://psm-ir.com/gemni/mb.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:04http://psm-ir.com/gemni/bd.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:04http://psm-ir.com/gemni/ob.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:07:04http://psm-ir.com/gemni/ab.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-08-23 18:06:05http://psm-ir.com/gemni/pen.exeOfflineNanoCore ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-08-23 20:58:05765ddf2da4feba42379d78e79fea5ad23a28a5de5d8359f18c9be28031a9ef5bexeRedLineStealer
2021-08-23 20:58:0533f0032493157313ad0c6adab971986df14022763e179997c495e039950d71d5exeRedLineStealer
2021-08-23 20:54:07146519fa04a20f7588d3ecac58bf5bd9f6061c17a9a246bd7bfadfd8ee8d818eexeRedLineStealer
2021-08-23 20:54:0558f465541e9fe204911a03c7c7bdf467327c1e448358a471beeb3bc898eb5666exeRedLineStealer
2021-08-23 20:54:054c8fb25ca2c5a4b5247188ff6da4620908d96fc4b19ba6c9ba7b7a9c1f7f2bf2exeRedLineStealer
2021-08-23 20:50:04a6da6ad9ccdb4a19150143345b42c6e30af534d300b5cf42e4bafe54c5a496bcexeRedLineStealer
2021-08-23 20:49:04a9f57838861052d6907c1ecae103fa5fed6dd1ac78156a7b41b9c80fe8247905exeRedLineStealer
2021-08-23 20:41:07eefb7c976c4962bef2c3553df1061326ccb68dca91224fe81b4cbcf93368bdbaexeRedLineStealer
2021-08-23 18:07:103afa2f6a6fa28303c9fd4bc4f9c6f5c7ba36c0c58a8d161c106228a919d2d8edexeAgentTesla
2021-08-23 18:07:0906c48a7afff810fd70a5e3214495f52b0794d7893fed5761565867982e287a61exeAgentTesla
2021-08-23 18:07:0560984e3b0494549fbbb8bd41bd79c370168bc76d750ada32e6c1af8619fa01d5exeAgentTesla
2021-08-23 18:07:04a8e95918b0b89f9c8eddfbea9c211c998719835b2efb91c418d463bda647916eexeAgentTesla
2021-08-23 18:07:04ab678f5bf745e3b2d1a5e7e07d88b3430c846e8c18068c4fe97329bef73ab5deexeAgentTesla
2021-08-23 18:07:0431feccf3da6fc04933d3ae09ff786132b5690c7f60cc8482f54b968b50a131e2exeAgentTesla
2021-08-23 18:07:0456f1f7df9b82c8bb7024f0c7cf699ff64b2f95014f72b5f8275af4d434e45479exeAgentTesla
2021-08-23 18:06:0532b2890cadb4788ceb05b0629329dd55aa7554c7f72d61157f06e445bfe31029exeNanoCore