URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: smtp.qwertzx.ru
Domain registrar:REG.RU -
Domain registration date:2022-04-11 09:15:27 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-02-08 07:18:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :144

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-20 08:59:18 31.177.76.32Not listedAS48287 RU-CENTER- RUno
2025-06-20 08:59:18 31.177.80.32Not listedAS48287 RU-CENTER- RUno
2024-04-24 22:41:17 194.67.71.167Not listedAS197695 AS-REGRU- RUno
2024-04-12 01:54:52 194.67.71.172Not listedAS197695 AS-REGRU- RUno
2024-04-26 09:27:55 194.67.71.154Not listedAS197695 AS-REGRU- RUno
2024-04-21 11:09:42 194.67.71.113Not listedAS197695 AS-REGRU- RUno
2024-04-29 20:08:18 194.67.71.178Not listedAS197695 AS-REGRU- RUno
2024-04-24 09:34:06 194.67.71.140Not listedAS197695 AS-REGRU- RUno
2024-04-26 02:18:32 194.67.71.171Not listedAS197695 AS-REGRU- RUno
2024-04-18 11:22:42 194.67.71.137Not listedAS197695 AS-REGRU- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-02-08 08:06:12http://smtp.qwertzx.ru/native.exeOffline32 CoinMiner exe Rhadamanthys zbetcheckin
2024-02-08 08:06:10http://smtp.qwertzx.ru/ghjk.exeOffline32 CoinMiner exe Rhadamanthys zbetcheckin
2024-02-08 08:06:05http://smtp.qwertzx.ru/asdf.EXEOffline32 CoinMiner exe Rhadamanthys zbetcheckin
2024-02-08 07:18:09http://smtp.qwertzx.ru/asdfg.exeOffline32 CoinMiner exe Rhadamanthys zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-04-07 08:03:1737423f57b1bd00b5ab8f21f679f35738dc066a37817804de9a362a142b3d5cdeexe  
2024-03-27 14:26:41432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67exeCoinMiner
2024-03-27 14:11:40432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67exeCoinMiner
2024-03-27 14:08:14432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67exeCoinMiner
2024-03-27 13:56:02432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67exeCoinMiner
2024-03-20 06:15:28cd9709a47f998a7dac16552b9af6c728c4d14dc6d174689cdd839bf67038028dexe  
2024-03-20 06:10:209b673d85e3eee6a10658e102741afe6331c9b57ad99348d4db73eee136491ec0exe  
2024-03-20 05:24:34dcbf84dfaa590c23b90d201574c9dc4ca96f73a6bf01f0db3f784bd3618848aeexe  
2024-03-20 04:44:0688d636d07935a0f7d25494f4482eee14a25b4bfbcc319612f2e9aa594e978ee8exe  
2024-03-20 04:20:15f6151286d2bdf8b0d2d5582e13bffb92d7e107d2c64df236eb6130409739e473exe  
2024-03-20 04:14:494586685a23da8211949d21b632a73267d7cb082f8fec37ccc49c50604c3b374cexe  
2024-03-20 03:20:050097cec808870ae6bcd3bf26e0c0e7cee83fc31af243cfc29f831af447907d25exe  
2024-03-20 01:15:098a5d02379fe562c2d254c8ed504fb46434601446b2ef4b925b9e78efb7a0c8ecexe  
2024-03-19 14:13:04d40bea48cb4a948e586a6fcaede6ba5cadc0197f33e123a7f0587453e436a649exe  
2024-03-19 14:12:116052a9c21fcfe7fa112634a5fb6139f2fa6c2a8345068cc5825a234424741da2exe  
2024-03-19 09:31:200a1a0e6eb4e5f028310ed9f4f6c706455572d5b53fbb5d4f8910252928105c05exe  
2024-03-19 06:52:54384f158c6986e43d7014de8840f9e006894a257d44dd5111278f758f0e3a3ea4exe  
2024-03-19 00:28:48677a935290780cc33cbe4fe3ca33028f0637a732feb705c593bb767619b44fe5exe  
2024-03-18 12:20:234dc4a5731364b47800189b82f0fe51fa1bda5ea828af59b57f22c88b7b13894eexe  
2024-03-18 06:29:51b453521f6646b621bf11c56988ef9b5f1a787333b05beb8aa3a330c2a8dec603exe  
2024-03-18 04:27:21aae346a5c9c9ffb7aae74d5bd26f8da4d08ea4d0a95ee5705db9d7d83aaffc8dexe  
2024-03-18 01:32:509320d7bb6dc2ebd7f0c9b73d56e6f533020685144346bdde3151082f4d583f35exe  
2024-03-18 00:18:5253995490e636a8b3fde7f36482493dbe2a54038a281d72d28c4b18d128d030f1exe  
2024-03-17 19:05:1517ac7627a6cd41de13d1b78345f3dd3b4a48adb7274800803a63a4e08d15d07cexe  
2024-03-17 16:43:15adfbb1a99f6c27d24943540fac36fecd417ead479ba434c2cdab8d5bbd9ecf0dexe  
2024-03-17 16:28:254dc4a5731364b47800189b82f0fe51fa1bda5ea828af59b57f22c88b7b13894eexe  
2024-03-17 13:21:15cc3297c939da3378fb8685a4403aa052c582ab0b72bc175bb7f34d55efa0844aexe  
2024-03-17 12:06:024dc4a5731364b47800189b82f0fe51fa1bda5ea828af59b57f22c88b7b13894eexe  
2024-03-17 03:54:328517fead203e3801181113434387c1093506cab704e6437de530e138511b1632exe  
2024-03-16 15:41:525fe454438ae1c33f24534030d9a2518d1f5eec40fe831ee4aa39c0188d98eaa4exe  
2024-03-16 11:22:2597649a7389fca455f24640bb714f824f8ccefb1fe8666dc017b6c93478a4ed1aexe  
2024-03-16 05:45:26abfff4c2953d4621f9724d1d73e3cf1909cf625ab00013d5e155143fcc7969edexe  
2024-03-16 01:11:276cf71c4072b6880d1b9ea23dbeeff785f21e29eb3ef7184b4a3c0e2218795c96exe  
2024-03-15 12:43:02fddd611c676c2a28c7968cb96c141fdadef8e7df6970d2fec066050089195b6cexe  
2024-03-15 12:02:39b5d4272b432044d058ad4eccff0e838e8d63986077640003bef3f84af71afc3dexe  
2024-03-15 01:05:35650f0248f6b9b3287e7bca580b50e435652ce809a59cd889596188e31711cbdeexe  
2024-03-14 17:10:16b15d823b55950a716641c51f939accf3306143fb1f8c3c0e19499aba738966b7exe  
2024-03-14 14:16:4513e72ecb16c10956fb9de212d482ae342f7f1d16c0c9b30c630e656bdf048791exe  
2024-03-11 01:07:528dcb834fb265f9973a39b8438f84202d0ea013071d53991010fd3bd54e7494fdexe  
2024-02-08 08:31:07217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92eexe Rhadamanthys
2024-02-08 08:06:12217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92eexe Rhadamanthys
2024-02-08 08:06:10217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92eexe Rhadamanthys
2024-02-08 07:18:09217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92eexe Rhadamanthys