URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: yapdiw06.top
Domain registrar:NICENIC -
Domain registration date:2021-12-27 10:46:41 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-07 12:17:09 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-01-07 12:17:10 92.223.105.70free.dsNot listedAS202422 GHOST- LUno
2022-01-07 23:14:40 91.224.22.230Not listedAS61317 ASDETUK- UAno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-07 14:23:10http://yapdiw06.top/downfiles/file.exeOffline32 cryptbot exe zbetcheckin
2022-01-07 12:17:10http://yapdiw06.top/download.php?file=file.exeOffline32 exe zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-07 17:40:55e69353b185a7f1fe20ea84f15f75e4aa11337aa39fed08c119c60780822849feexeCryptBot
2022-01-07 14:23:1033058aed960aee7a6c3df8f0dee358b3ca819c4ce9553afdd22bea022c6801b9exeCryptBot