URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | qwdfewf.com |
|---|---|
| Domain registrar: | REG.RU ![]() |
| Domain registration date: | 2024-09-28 19:53:32 UTC |
| Spamhaus DBL : | Not blocked |
| SURBL : | Not blocked |
| Quad9 : | Status unknown |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Status unknown |
| OpenBLD : | Blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2024-10-18 09:11:04 UTC |
| Total malware sites : | 2 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 2 (100%) |
| A record(s) observed : | 20 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-09-28 22:49:51 | 194.67.71.116 | Not listed | AS197695 AS-REGRU | RU | no | |
| 2025-01-02 08:55:37 | 94.156.227.145 | Not listed | AS50837 CLOUDSIGMA-AS | SA | no | |
| 2024-11-16 00:25:56 | 185.216.71.118 | Not listed | AS215439 PLAY2GO-NET | FI | no | |
| 2024-10-27 10:58:41 | 193.46.217.43 | Not listed | AS400992 ZHOUYISAT-COMMUNICATIONS | US | no | |
| 2024-10-27 01:42:59 | 165.22.67.187 | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no | |
| 2024-10-25 15:21:21 | 213.178.155.106 | Not listed | AS214822 MTFINANCE-AS | RU | no | |
| 2024-10-24 14:51:30 | 164.92.242.65 | Not listed | AS14061 DIGITALOCEAN-ASN | DE | no | |
| 2024-10-21 19:42:29 | 45.144.174.5 | Not listed | AS26383 ASNET | HK | no | |
| 2024-10-18 12:15:39 | 212.192.12.176 | Not listed | AS26383 ASNET | HK | no | |
| 2025-09-30 16:48:34 | 194.67.71.125 | Not listed | AS197695 AS-REGRU | RU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2024-10-18 09:11:10 | http://qwdfewf.com/dwn_payload_file | Offline | exe | |
| 2024-10-18 09:11:09 | http://qwdfewf.com/dwn_legit_file | Offline | exe RemcosRAT |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2024-10-18 09:11:08 | 06363ca6381d7c68f453b58f0566966caa9169c25dea626cfcb7001a3dd7bc5f | exe | RemcosRAT | |
| 2024-10-18 09:11:07 | 76efb280fc1d0ddf376aef018f26f3185fbd80990fb283ff02f522ead480b207 | exe |

SA
FI
US
DE
HK