URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: race.ydns.eu
Domain registrar: n/a
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2023-06-10 10:11:08 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-02 00:32:47 94.156.65.252taeniada252.nonsexual94.builder-marketing.comNot listedAS208893 sparks- GByes
2023-08-30 08:23:40 193.42.32.61Not listedAS214396 SUDOLIO-AS- SKno
2023-06-10 10:11:09 85.209.134.253Not listedAS41745 FORTIS-AS- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-06-10 10:11:09http://race.ydns.eu/rate/saw.comOfflinePureCrypter abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-06-14 04:56:0101b22c6616dab755850192f2580e982635a28dbb98b868e36cbb483a15da90a4exe  
2023-06-13 15:02:43434059c2dd4abfb50b823671edb43696e4363e55692f913c1da856f9a1ecf6c3exe  
2023-06-12 05:51:57085758594b8004ffcd2c0b7413d67c3fd8024d8915aac54b95db59609c7bd55dexePureCrypter
2023-06-11 06:55:047aae9c3c1ffb5983de4c595a757f5f3d970ee895a17948aa17394cabd2910d78exePureCrypter
2023-06-10 10:11:0922cdb432f7d20f06b120789c7f089f7b376d02a7d1576b3ab0e31456376ef47bexe