URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: swretjhwrtj.gq
Domain registrar:Freenom -
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2021-08-24 11:44:02 UTC
Total malware sites :31
Online malware sites :0 (0%)
Offline Malware sites :31 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-08-31 19:43:49 45.66.10.29free.example.comNot listedAS211381 PODAON- NLno
2021-08-24 23:16:18 104.21.46.21Not listedAS13335 CLOUDFLARENETn/ano
2021-08-24 23:16:19 172.67.222.157Not listedAS13335 CLOUDFLARENETn/ano
2021-08-24 11:44:04 104.21.86.82Not listedAS13335 CLOUDFLARENETn/ano
2021-08-24 11:44:04 172.67.216.236Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-09-02 12:49:03http://swretjhwrtj.gq/reviewDriverSavesintoHost...Offline32 dcrat exe zbetcheckin
2021-09-02 12:49:03http://swretjhwrtj.gq/acd.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-09-02 12:49:03http://swretjhwrtj.gq/PowerShells.exeOfflineexe zbetcheckin
2021-09-02 12:49:03http://swretjhwrtj.gq/ShellExperienceHostss.exeOfflineexe zbetcheckin
2021-09-02 12:42:13http://swretjhwrtj.gq/build.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-09-02 12:42:03http://swretjhwrtj.gq/isnlod.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-09-02 12:42:03http://swretjhwrtj.gq/11.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-09-02 12:42:03http://swretjhwrtj.gq/GoogleGoogle.exeOffline32 ArkeiStealer ext exe zbetcheckin
2021-09-02 12:42:03http://swretjhwrtj.gq/test.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-09-02 12:42:02http://swretjhwrtj.gq/xqw.exeOffline32 exe zbetcheckin
2021-08-27 04:19:05http://swretjhwrtj.gq/111.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-08-27 03:05:05http://swretjhwrtj.gq/zxsa.exeOffline32 ArkeiStealer ext exe zbetcheckin
2021-08-27 03:05:05http://swretjhwrtj.gq/savesrefcrtDllsavesCrtdhc...Offline32 dcrat exe zbetcheckin
2021-08-25 21:32:05http://swretjhwrtj.gq/ZXCXZCsssssssssssASDFasdf...Offline32 CoinMiner exe zbetcheckin
2021-08-25 19:04:03http://swretjhwrtj.gq/B555uild.exeOffline32 ArkeiStealer ext exe zbetcheckin
2021-08-25 05:46:06http://swretjhwrtj.gq/proliv75.exeOfflineRedLineStealer ext zbetcheckin
2021-08-25 01:46:05http://swretjhwrtj.gq/aqwcccccccczxc.exeOfflinedcrat zbetcheckin
2021-08-24 22:10:03http://swretjhwrtj.gq/CD.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 22:05:04http://swretjhwrtj.gq/v2.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 22:01:07http://swretjhwrtj.gq/1.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 21:43:07http://swretjhwrtj.gq/arasholit.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 18:48:04http://swretjhwrtj.gq/autorun.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 15:15:03http://swretjhwrtj.gq/system.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 15:02:07http://swretjhwrtj.gq/CPU.exeOfflineCoinMiner zbetcheckin
2021-08-24 14:02:04http://swretjhwrtj.gq/Downloader.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 13:58:05http://swretjhwrtj.gq/v1.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 13:45:05http://swretjhwrtj.gq/@Rarenut0.exeOfflineRedLineStealer ext abuse_ch
2021-08-24 13:45:04http://swretjhwrtj.gq/Buld2.exeOfflineRedLineStealer ext abuse_ch
2021-08-24 13:41:07http://swretjhwrtj.gq/GPU.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 13:41:05http://swretjhwrtj.gq/PerfmonitordriverCommon.exeOfflineRedLineStealer ext zbetcheckin
2021-08-24 11:44:04http://swretjhwrtj.gq/JJJWOWOW.exeOfflineArkeiStealer ext RedLineStealer ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-09-02 12:49:034b648c17bb169cf81da7a4d1182238b96463ed58474ef6b539818fdb19291a32exeDCRat
2021-09-02 12:49:03b7c646c4dfa6a14915e1e003460c9f8acfa8addee9e5e5856476ebb84ac90a64exeRedLineStealer
2021-09-02 12:42:135d124c343ca289f13081d3b447859ef55da2562c3ae650e984995f68c26b1a97exeRedLineStealer
2021-09-02 12:42:03a5e7fc18a5e344a7f398d03f8b4e2cf0f2579e4d70c90915376e066cec01505aexeRedLineStealer
2021-09-02 12:42:037c78dc5ccbdff7e949fed9b04fcfd5a3b312f0fe950441094d77e8bdbf393491exeRedLineStealer
2021-09-02 12:42:036c011b07a1ea9b18709ea1604b54821ccd1cf10b5e82032bb9a722199d8357c5exeArkeiStealer
2021-09-02 12:42:0339fb0e426b3a793c3e3eadc0a8ddb93f5639ac2b9c98ffc9e66e27fbc01fdcf1exeRedLineStealer
2021-09-01 17:27:54ccfe8fddce9f17fd8851a62d3e7d0e2610982e834d2401673b6d16eaac5e684bexe RedLineStealer
2021-08-27 04:19:05a32770d46ee2ee5b91cc36e5159868ec3ff7f847e7516d7bcb952f7a94e347a2exeRedLineStealer
2021-08-27 03:05:05382dbb2ef5f54e3735817318b680935e068749651f702213ab3edfb7842115fdexeArkeiStealer
2021-08-27 03:05:05d7fa1b64c4a5a79700791c113b5b2594a2194a8ca83bf18494337ef12d88fdb6exeDCRat
2021-08-25 21:32:0524b35ddd2195133e968aeed816c92367a47413f58506138e75441446be1524deexeCoinMiner
2021-08-25 19:11:50bc99b42680a19379e7030dc0871c143afd142ccb9b12efd2942a97e706f7dd59exeArkeiStealer
2021-08-25 05:46:0651442e324f993001dbfaa1ed17ff119b0f392f22e47a1835d89514cd1d77c027exeRedLineStealer
2021-08-25 01:58:50105f84831dddedb6f03fd79e892afaa1fed238b4f7538058f45fa28e10cb244bexeDCRat
2021-08-24 22:53:253fe1eb9d42f269e15ac61afb0869f64ee4436d47521aee29035a8cff2c632af5exeRedLineStealer
2021-08-24 22:05:049c1ddfa908ee08b1e2efedc8a6e9a00cccbaa941a927f210fb15ea0ad781b57eexeRedLineStealer
2021-08-24 22:01:070a17ef3263b6b35cb6a99754dcd6349922d3a377de87c9a0516c284a4082b3ebexeRedLineStealer
2021-08-24 21:43:077f5f108eabea4020022851e2dc521b16e7e46c13b7935e4269c0eef2df7341ecexeRedLineStealer
2021-08-24 18:48:04e7e2a6b03469fb8c542986035a5a67997e1afc3e78d93f267028db4672c68207exeRedLineStealer
2021-08-24 15:34:442e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 15:02:0533a236fd56543bf3915e16cfffb3c6a4b0f92c9ba444744339e3bcc10f285d61exeCoinMiner
2021-08-24 14:02:042e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 13:58:052e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 13:45:052e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 13:45:044e8c517dc9e0d8e4c5b95dd953f86391068ed00b1b758fe044fe5771d38b6184exe RedLineStealer
2021-08-24 13:41:07d6dff5118d406d4e4c9ba203af253c4a6e5a18683e466a6d4109d75c7307554aexeRedLineStealer
2021-08-24 13:41:052e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 12:35:262e1064e3bd2d37cd96495c01f326d4a543b77e38045a983e93e99a4704df206fexe RedLineStealer
2021-08-24 11:44:03386cb4a88b5c465c29db7093db94fe6b8e30bb41c2d994569b1fc05d9b1b82d2exeArkeiStealer