URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 1.246.222.249
Firstseen:2020-02-04 14:08:56 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-02-04 14:08:59 1.246.222.249Not listedAS9318 SKB-AS- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-05 16:34:06http://1.246.222.249:1157/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-12-17 03:34:09http://1.246.222.249:3477/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-12-15 19:04:07http://1.246.222.249:3477/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-10-31 21:26:35http://1.246.222.249:2837/Mozi.aOfflinemirai ext Mozi ext Petras_Simeon
2021-10-22 13:33:08http://1.246.222.249:4236/iOfflineMozi ext Petras_Simeon
2021-10-14 16:19:07http://1.246.222.249:4236/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-08-13 04:49:06http://1.246.222.249:1157/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-07-10 22:22:54http://1.246.222.249:3847/iOfflinemirai ext Petras_Simeon
2021-04-17 01:19:11http://1.246.222.249:3847/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-15 02:34:06http://1.246.222.249:2984/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-12 03:04:05http://1.246.222.249:2984/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-08-12 10:41:27http://1.246.222.249:1137/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-06-05 01:27:28http://1.246.222.249:1137/Mozi.mOfflinemirai ext Mozi ext Gandylyan1
2020-05-09 20:29:05http://1.246.222.249:2837/Mozi.mOfflinebashlite elf gafgyt ext mirai ext zbetcheckin
2020-03-23 03:03:11http://1.246.222.249:4094/Mozi.mOfflineelf mirai ext Mozi ext Gandylyan1
2020-02-04 14:08:59http://1.246.222.249:3847/Mozi.mOfflineelf mirai ext Mozi ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-05 16:34:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-12-17 03:34:09e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-12-15 19:04:07e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-10-31 21:26:35e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-10-14 16:19:07e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-08-13 04:49:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-07-10 22:22:54e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-04-17 01:19:11e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-01-08 16:09:19f8fd549477f4e93fe88f9ef47768e227a2d326d774c765c9d3021f6afbe74092elf  
2020-12-15 02:34:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-12-12 03:04:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-08-12 10:41:27e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-06-05 01:27:28e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-05-09 20:29:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-03-23 03:03:11e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-02-04 14:08:59e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai