URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: russk21.icu
Domain registrar:Namecheap -
Domain registration date:2022-02-15 17:26:49 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-05-20 12:29:03 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-20 06:25:20 3.222.192.211ec2-3-222-192-211.compute-1.amazonaws.comNot listedAS16509 AMAZON-02- USyes
2022-07-01 21:28:25 194.195.116.114194-195-116-114.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- INno
2022-06-30 18:20:54 45.86.86.142port3.mixNot listedAS200019 AlexHost- MDno
2022-05-31 23:48:54 45.147.231.107SBL517021AS30823 AUROLOGIC- DEno
2022-05-22 10:37:11 64.44.102.207207-102-44-64.reverse-dnsNot listedAS20278 NEXEON- USno
2022-05-20 12:29:05 172.93.179.212212-179-93-172.reverse-dnsNot listedAS20278 NEXEON- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-19 16:59:04http://russk21.icu/mailo/netinfo.exeOffline32 exe XFilesStealer zbetcheckin
2022-07-19 15:04:11http://russk21.icu/ex2.exeOfflineexe abuse_ch
2022-06-06 06:12:04http://russk21.icu/AScan.exeOffline32 exe XFilesStealer zbetcheckin
2022-06-06 06:02:06http://russk21.icu/ex.exeOffline32 exe zbetcheckin
2022-05-20 12:34:03http://russk21.icu/mailo/socks.exeOfflineee SystemBC ext abuse_ch
2022-05-20 12:29:05http://russk21.icu/autosqli.exeOfflineexe abuse_ch
2022-05-20 12:29:05http://russk21.icu/mailo/ex.exeOfflineexe abuse_ch
2022-05-20 12:29:05http://russk21.icu/mailo/pass.exeOfflineee abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-19 21:22:55761a54ace7ed14821e9aedb827914de33f6c5247c15c908060089eaaad0d3144exe  
2022-07-19 16:59:04deccabcc57c6a41b9e2e1f3f97b9425831304f69387299adf1405350d2f5d110exeXFilesStealer
2022-07-19 15:04:11ff02cd57ce67f7363cb67aee7fefd1d4e11e6f12399072b158e1f575e4b52846exe 
2022-07-15 18:56:09536790762a26ed9103e1f647186467f9a6a742102674f62585a2735d64bfc50eexe  
2022-07-07 21:41:5985eb988ee7a039621da5bf44432b9c472836092fabb94e675b32890bf9c06d4eexe XFilesStealer
2022-06-28 02:28:321f68e889d3c4c7f8049bad4abd042fcd05e84ac96bf23d86e2e95aa8fe346593exe 
2022-06-18 03:21:30b24bcecff3bf317920baac78f94c18dd3452a9f40eabf3ea57493365653b2dbeexe  
2022-06-18 01:37:39bbd14055793976d6fbc8792739ae3725b80df2536a88efdbbbdf3813a2ba972aexe  
2022-06-17 21:55:333082581dfca1f8d01b1ad4bdad74c12893ca9baeecb915d4ba70d14caf81c27cexe  
2022-06-17 06:19:456c4a14186bd50f8935687f60a2bfac4c6512a26f6766923ef1d816a59c1d020aexe  
2022-06-16 09:18:049c96bad250333fd0da7c708bf36dc1d9bb93fcdf418325bf5cf7299aeb9bcb2eexe  
2022-06-15 08:27:252c5f9bc36f81b076c3db6aaff6feeb1fa969d31c701e1ae6365e18ae014f453cexe  
2022-06-10 19:28:44da9d5faed8995eac06f760ad0dd37498721e1bc89a1121ee31914da657dc9501exe  
2022-06-10 06:56:0797816e9d1588aa0d55ca3a7de289c54a813ee9c2dfc01d7f14431697f5b4101dexe  
2022-06-06 06:12:04d49cb57411da2fedea6b7e89b083282afa86342d97e9b31aa5ec58e6f9f01618exe 
2022-06-06 06:02:063da7dccc0e92c7324dea07df10ba938dd21f4436e9b8dd20488517b5eff67676exe 
2022-06-05 09:02:15880122544a0eac1adb8fde0bab910123d4399631b8a0ad78d8cf78e088980547exe 
2022-06-05 06:49:418b3ae2c1e6349c4bc29e61aef103f540fc18b76495ee0328c85efb8ddf5bfd62exe  
2022-06-04 08:34:2975d8d919c47b24b3fdd61006b3bc546af3cfbafe618ebd2f8848aec289b5c7a7exe  
2022-06-04 07:49:27a084c540c0f847784592d7834f600299bb48c7ecaf948bf4f7897bcab8ead657exe  
2022-06-03 10:43:261acba777a2fc67f53f56ddead631b9dd23bab2cbcca1c991b2553f413dc9eb42exe  
2022-06-03 10:10:175b8ec10e01e2a4ac5d5e86454b176f78081f3f2717d8ae0a7d757b851a4d2613exe  
2022-05-26 11:48:002c24172c94ed3259430d2bbb2c3eaaf866e08274ec484782e79990e085a7966bexe  
2022-05-23 10:08:25aafef6393a6a8acb281c4773ec22ef6ac3f348ddf49eabfa6adf8da29f6c5211exe  
2022-05-20 12:34:030e56c159b8c4fe60ee4a9d9bac1118c9467965086d1de239e1b27ecbbe540182exeSystemBC
2022-05-20 12:29:05ff82f652f0c3454ead15a3d2e0b550353ffd2c5839f0ba4fc3095a8209798d69exe 
2022-05-20 12:29:05b718e33a2ca58e4da31bbab3e6fa086aee66040b863da973f0c55070ee22921aexe 
2022-05-20 12:29:040b848654c8ea5a8d75b4c881c84df31cf856fa212c032452e74ccc906b9367e1exe