URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | w6s.ru |
|---|---|
| Domain registrar: | REG.RU ![]() |
| Domain registration date: | 2025-10-16 07:19:56 UTC |
| Abuse complaint sent to registrar: | Yes (2025-10-25 15:07:02 UTC to abuse{at}reg[dot]ru) |
| Domain registry: | Coordination Center for TLD RU ![]() |
| Abuse complaint sent to registry: | Yes (2025-10-25 15:07:02 UTC to ru-adm{at}cctld[dot]ru) |
| Spamhaus DBL : | Abused domain (malware) |
| SURBL : | Not blocked |
| Quad9 : | Blocked |
| AdGuard : | Blocked |
| Cloudflare : | Blocked |
| ProtonDNS : | Blocked |
| OpenBLD : | Blocked |
| DNS4EU : | Blocked |
| Control D HaGeZi : | Not blocked |
| Firstseen: | 2025-10-25 15:04:05 UTC |
| Total malware sites : | 8 |
| Online malware sites : | 0 (0%) |
| Offline Malware sites : | 8 (100%) |
| A record(s) observed : | 2 |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-11-22 15:59:23 | 77.221.154.221 | dispensablequiver.ptr.network | SBL655597 | AS210644 AEZA-AS | NL | yes |
| 2025-10-25 15:04:09 | 78.153.140.124 | bestmerketings.click | SBL655362 | AS202306 HOSTGLOBALPLUS-AS | GB | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-11-23 10:43:18 | http://w6s.ru/b1n/arm6 | Offline | botnetdomain elf mirai | |
| 2025-11-23 10:43:14 | http://w6s.ru/b1n/arm | Offline | botnetdomain elf mirai | |
| 2025-11-23 10:43:12 | http://w6s.ru/b1n/mips | Offline | botnetdomain elf gafgyt | |
| 2025-11-23 10:43:12 | http://w6s.ru/b1n/arm5 | Offline | botnetdomain elf mirai | |
| 2025-11-23 10:43:11 | http://w6s.ru/b1n/x86 | Offline | botnetdomain elf mirai | |
| 2025-11-23 10:43:11 | http://w6s.ru/b1n/arm7 | Offline | botnetdomain elf mirai | |
| 2025-11-23 10:43:11 | http://w6s.ru/b1n/mpsl | Offline | botnetdomain elf gafgyt | |
| 2025-10-25 15:04:09 | http://w6s.ru/f | Offline | geofenced mirai |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-11-23 10:43:18 | 7f424b4c5bd2c14bc90380f25f64092c2ceff53b78a3194adb6f0fafa71bb4a0 | elf | Mirai | |
| 2025-11-23 10:43:14 | 607ba8678ec0bedb0370c99a382fcada0a60080d2258f59d330915f4b0dae33a | elf | Mirai | |
| 2025-11-23 10:43:12 | 20e959be15a37128a15848f805f1dd984f8f784c9b0b47a8fb76461b754c0505 | elf | Mirai | |
| 2025-11-23 10:43:11 | 9e65eca49315d1425c7d8a156202fdb0629d1557ed1102bc960991a34d565651 | elf | Mirai | |
| 2025-11-23 10:43:11 | 5d599bd71f9fc3ed8fb117dad0af6ff00c502560ef61dd35aa5dd70b204e903f | elf | Mirai | |
| 2025-11-23 10:43:11 | 3c819078a12972e4ecfae0362c13747a0cbea67603271497eaef71d17a6592a9 | elf | Gafgyt | |
| 2025-11-23 10:43:11 | 3256836c9f7cac124ff021679e7b2947b1633793c85c4251bae4b67b23081ee2 | elf | Gafgyt | |
| 2025-10-25 15:04:09 | 1fa35c23b8830fdef00fca8e03eda8994879970e808b806914897b3ad98310ec | sh | Mirai |

NL
GB