🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: royalcuts.co.uk
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-09-21 13:00:10 UTC
Total malware sites :5
Online malware sites :3 (60%)
Offline Malware sites :2 (40%)
Newest active malware site :2026-09-24 13:37:19 UTC
Oldest active malware site :2026-09-21 13:01:17 UTC (Age: 4 days, 16 hours, 41 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-09-21 13:01:14 173.254.56.14rsj14.rhostjh.comNot listedAS46606 UNIFIEDLAYER-AS-1- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-09-24 13:37:19https://royalcuts.co.uk/google.exeOnline adrian__luca
2026-09-21 13:01:24https://royalcuts.co.uk/Chrome.exeOnlineCoinMiner adrian__luca
2026-09-21 13:01:20https://royalcuts.co.uk/3.exeOfflineCoinMiner adrian__luca
2026-09-21 13:01:17https://royalcuts.co.uk/ChromeSetup.exeOnline adrian__luca
2026-09-21 13:01:14https://royalcuts.co.uk/Setup.exeOffline adrian__luca

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-09-24 13:37:196f21b609ec46ec04b046bc20406931cb1f62916e427500eb1716cc43a86165daexe 
2026-09-24 12:00:31d2308ce690cdcc2a36398b46275c093afb4cfb8360324516f331cde41b5280e3exe  
2026-09-24 11:44:14a79f714e8c2239baa9f1bfef2e0eedf1373fca1b63e2de8c99e04ce0d183c7d8exe  
2026-09-24 07:52:31dcad58bd855b9b025cf8df4bf440dd0dd927dc641588ea56ad272e88c312996cexe  
2026-09-24 05:34:091a614e6c4733e900fafb2cd511c2c5e25c326b88a146eb5fac8d08a642a33eedexe  
2026-09-24 05:06:48ab60822572ae0c31a19187ec99094682bc09f99e88962864aecb8e5e469a6f62exe  
2026-09-24 04:29:31bc9b6995300862e4140372a468082555e621d29454ea5f43ea7e9b02cdcd95c2exe  
2026-09-24 04:14:27a0c3d3a0a7e98d405e7790f5b4d4129479f340863547d4a59e712d413cd429d5exe  
2026-09-24 04:06:3384d71d6fe0ec5c29f6bb5eda5aa1a093ad8c73907f880637c9603567bbfe0677exe  
2026-09-24 00:14:4945627a26c5fdb3eb090f593e35393fa57467c0312c27568aa4824048bd2b6be9exe  
2026-09-23 22:36:0938311a3ca87cdc769632d7955f0ecc0471309b7240780c2a58fa3216f568c828exe  
2026-09-23 17:46:45083064dacd6619ef207dfb674cf67af146119ec640dfa432bd5bea1ac0f2df7eexe  
2026-09-23 16:52:250e03982f1335013b618406ad47181315279401b2d29cecc6ea6bc796ce02ad5bexe  
2026-09-23 14:15:3487d61ef22a9b4dcf47511228dab17a117912c723fb8d996395660ca43e6ff259exe  
2026-09-23 11:58:56efda9ed7258e319d1b481063670a523675ab9f76676724da332132bac6507925exe  
2026-09-23 10:16:382547138e7138b87794fa01aa287fff646cedc5b486ec855de526a36d0222f846exe  
2026-09-23 04:22:3688a68b4f97b89818841f6d5b121ab67591f4b96baed7babc4f073d30b062b1dbexe 
2026-09-22 16:48:39692581e015122cbee3e114e510c07982731fd084eaf1a875482b122163d01e1eexe  
2026-09-22 16:42:587b45264d9359bec670259055114c4d1952be468e016c7d13f81a25f31fae45e4exe 
2026-09-21 13:01:247618324f0ee19ea02ac6dd84246501c3de6a4e10d529c63a3a2ce224efd11f24exeCoinMiner
2026-09-21 13:01:197cf2024df87ba1cb23e2db17b154ecd693318dd167a935467c86f57e57c88897exeCoinMiner
2026-09-21 13:01:16e5a82ebf4dd608cb8017e809cf511cdb125d48602a093deda33239d8d35ebe0fexe