############################################################################## # URLhaus ASN CSV Feed # # Generated on 2026-05-28 17:28:44 UTC # # # # For questions please refer to: # # https://urlhaus.abuse.ch/feeds/ # ############################################################################## # # Feed generated for AS21769 # # Dateadded (UTC),URL,URL_status,Threat,Tags,Host,IPaddress,ASnumber,Country "2026-04-14 19:28:18","http://184.174.20.150:8040/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=bat&c=&c=&c=&c=&c=&c=&c=","online","malware_download","ConnectWise","184.174.20.150","184.174.20.150","21769","US" "2026-02-20 17:00:22","http://173.211.70.196:443/02.08.2022.exe","offline","malware_download","censys|CobaltStrike","173.211.70.196","173.211.70.196","21769","US" "2026-01-11 08:03:10","http://184.174.32.240:9000/bpexch_implant_linux","offline","malware_download","Sliver","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:36:11","http://184.174.32.240:9000/sliver-client_linux-amd64","offline","malware_download","opendir|Sliver","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:36:09","http://184.174.32.240:9000/sliver_linux_9999.elf","offline","malware_download","opendir|Sliver","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:36:00","http://184.174.32.240:9000/sliver_linux_implant.elf","offline","malware_download","opendir|Sliver","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:35:38","http://184.174.32.240:9000/one_liner.sh","offline","malware_download","opendir|Sliver","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:35:22","http://184.174.32.240:9000/sliver-client_linux-amd64.minisig","offline","malware_download","opendir","184.174.32.240","184.174.32.240","21769","FR" "2026-01-11 06:35:07","http://184.174.32.240:9000/stager.b64","offline","malware_download","opendir","184.174.32.240","184.174.32.240","21769","FR" "2025-12-11 16:12:21","https://whost.kyun.li/1e17bdb390a91eee.msi","offline","malware_download","","whost.kyun.li","66.78.40.254","21769","US" "2025-10-10 13:39:06","https://amphetamine.kyun.li/?cid=779461502770a6d","offline","malware_download","ascii|js","amphetamine.kyun.li","66.78.40.254","21769","US" "2025-09-09 06:07:15","http://180.131.145.148:12345/CONFIDENT_STRING.exe","offline","malware_download","Sliver","180.131.145.148","180.131.145.148","21769","US" "2025-09-09 06:07:15","http://180.131.145.148:12345/WEAK_REQUEST.exe","offline","malware_download","Sliver","180.131.145.148","180.131.145.148","21769","US" "2025-09-09 06:07:06","http://180.131.145.148:12345/sch.exe","offline","malware_download","","180.131.145.148","180.131.145.148","21769","US" "2025-09-07 13:30:19","http://66.78.40.221/kitty.armv7","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.armv5","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.armv6","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.mips","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.mipsel","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.x86","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:15","http://66.78.40.221/kitty.x86_64","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-07 13:30:07","http://66.78.40.221/kitty.aarch64","offline","malware_download","elf|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:47:15","http://66.78.40.221/router.zyxel.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/ipcam.tplink.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.aarch64","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.armv5","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.armv6","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.mips","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.mipsel","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.x86","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/kitty.x86_64","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/router.tplink.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/bins/router.zyxel.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:20","http://66.78.40.221/ipcam.tplink.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:15","http://66.78.40.221/bins/kitty.armv7","offline","malware_download","elf|Mirai|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-09-06 17:46:15","http://66.78.40.221/router.tplink.sh","offline","malware_download","sh|ua-wget","66.78.40.221","66.78.40.221","21769","US" "2025-02-19 17:46:04","http://45.40.96.159:8080/TaxDocument/Retum%20off%20Organization%20Exempt%20From%20Income%20Tax.pdf%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Adobe%20Acrobat%20Document.lnk","offline","malware_download","AsyncRAT|ps1|PSLoramyra|script|vbs","45.40.96.159","45.40.96.159","21769","US" "2025-02-12 19:00:06","https://216.107.136.186/check-it/report","offline","malware_download","Emmenhtal|hta","216.107.136.186","216.107.136.186","21769","US" "2024-10-10 23:08:23","http://67.203.7.163:1244/pdown","offline","malware_download","BeaverTail|Lazarus|py|StrelaStealer|zip","67.203.7.163","67.203.7.163","21769","US" "2024-06-28 11:27:34","http://45.40.96.164/rat/server/rbackup.txt","offline","malware_download","Base64|opendir|Rat|RemcosRAT|rev-base64-loader","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:34","http://45.40.96.164/rat/server/venom_teste.txt","offline","malware_download","Base64|base64-loader|opendir|QuasarRAT|Rat","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:09","http://45.40.96.164/rat/server/vbackup.txt","offline","malware_download","Base64|opendir|QuasarRAT|Rat|rev-base64-loader","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:08","http://45.40.96.164/rat/dll/vrump.txt","offline","malware_download","base64-loader|obfuscated|opendir|Rat","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:07","http://45.40.96.164/rat/server/anybackup.txt","offline","malware_download","AsyncRAT|Base64|opendir|Rat|rev-base64-loader","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:07","http://45.40.96.164/rat/server/anyhnvc.txt","offline","malware_download","Base64|opendir|Rat|rev-base64-loader","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:06","http://45.40.96.164/rat/dll/vdll.txt","offline","malware_download","base64-loader|obfuscated|opendir|Rat","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:06","http://45.40.96.164/rat/dll/ventrypoint.txt","offline","malware_download","obfuscated|opendir|Rat","45.40.96.164","45.40.96.164","21769","US" "2024-06-28 11:27:05","http://45.40.96.164/rat/server/extrato_venom.txt","offline","malware_download","Base64|opendir|Rat","45.40.96.164","45.40.96.164","21769","US" "2024-06-11 19:05:10","http://67.207.166.175/xampp/gts/BrowserUpdate.hta","offline","malware_download","CobaltStrike|hta","67.207.166.175","67.207.166.175","21769","US" "2024-06-07 03:49:05","http://67.207.166.175/M0306T/lsass.exe","offline","malware_download","32|exe|PureCrypter","67.207.166.175","67.207.166.175","21769","US" "2024-06-06 14:59:06","http://67.207.166.175/T0406W/lsass.exe","offline","malware_download","exe|opendir|PureCrypter|PureLogStealer","67.207.166.175","67.207.166.175","21769","US" "2024-06-06 14:58:07","http://67.207.166.175/xampp/gbh/lionsarekingogthejunglewhorulestheentireforestandlionsgreattounderstandtheyaregreattoundersetandlionsarekindofthejungle__lionsarekingofjungle.doc","offline","malware_download","doc|PureCrypter|PureLogStealer","67.207.166.175","67.207.166.175","21769","US" "2024-04-30 10:30:18","http://67.203.7.154/uigcLHxYEyYHi246.bin","offline","malware_download","","67.203.7.154","67.203.7.154","21769","US" "2023-10-24 10:41:08","http://45.40.96.248/img/bola.txt","offline","malware_download","RemcosRAT","45.40.96.248","45.40.96.248","21769","US" "2023-01-10 16:19:38","http://208.76.253.84/ga.exe","offline","malware_download","exe","208.76.253.84","208.76.253.84","21769","US" "2021-11-30 04:51:17","http://marymotherofmercyivf.com/perspiciatisprovident/similiqueet-149849329","offline","malware_download","chaserldr|Qakbot|TR|zip","marymotherofmercyivf.com","173.214.176.25","21769","US" "2021-11-03 17:08:09","http://lawfirm.paperbirdtech.com/chimney.php","online","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-11-03 15:56:04","http://lawfirm.paperbirdtech.com/toggle.php","offline","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-10-19 16:47:10","https://marymotherofmercyivf.com/perspiciatisprovident/documents.zip","offline","malware_download","TR|zip","marymotherofmercyivf.com","173.214.176.25","21769","US" "2021-09-09 04:19:05","http://lawfirm.paperbirdtech.com/promethium.php","online","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-09-08 15:18:04","http://lawfirm.paperbirdtech.com/photon.php","online","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-09-08 15:18:02","http://lawfirm.paperbirdtech.com/philanthropic.php","online","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-09-08 15:06:04","http://lawfirm.paperbirdtech.com/wash.php","online","malware_download","doc|hancitor|html","lawfirm.paperbirdtech.com","184.174.39.217","21769","FR" "2021-06-30 04:04:09","http://103.71.61.45:50942/Mozi.m","offline","malware_download","elf|Mirai|Mozi","103.71.61.45","103.71.61.45","21769","US" "2021-06-24 07:34:16","http://103.71.61.45:43860/Mozi.m","offline","malware_download","elf|Mirai|Mozi","103.71.61.45","103.71.61.45","21769","US" "2021-05-11 11:19:19","http://103.108.97.51:49676/Mozi.m","offline","malware_download","elf|Mirai|Mozi","103.108.97.51","103.108.97.51","21769","US" "2018-12-06 21:51:05","http://173.46.85.239:4560/aza.msi","offline","malware_download","msi","173.46.85.239","173.46.85.239","21769","US" "2018-12-04 17:20:06","http://173.46.85.239:4560/k900.msi","offline","malware_download","Lokibot","173.46.85.239","173.46.85.239","21769","US" "2018-11-30 21:20:04","http://173.46.85.239:4560/press.exe","offline","malware_download","exe|Pony","173.46.85.239","173.46.85.239","21769","US" "2018-11-30 09:09:15","http://173.46.85.239:4560/fis2.exe","offline","malware_download","exe|Pony","173.46.85.239","173.46.85.239","21769","US" "2018-11-30 09:09:13","http://173.46.85.239:4560/metu.exe","offline","malware_download","exe|Pony","173.46.85.239","173.46.85.239","21769","US" "2018-11-29 19:26:36","http://173.46.85.239:4560/kate.exe","offline","malware_download","exe|Loki","173.46.85.239","173.46.85.239","21769","US" "2018-11-22 17:14:03","http://zp1.duckdns.org:6060/pr.jar","offline","malware_download","adwind|jar","zp1.duckdns.org","173.46.85.179","21769","US" # of entries: 73