URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 1.246.223.4
Firstseen:2021-01-11 15:34:44 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-23 15:06:21 1.246.223.4Not listedAS9318 SKB-AS- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-04 15:49:15http://1.246.223.4:2221/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2023-01-16 11:19:22http://1.246.223.4:2686/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2022-06-15 18:49:07http://1.246.223.4:3933/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2022-05-25 01:04:05http://1.246.223.4:2221/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2022-04-28 15:49:05http://1.246.223.4:3933/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-10-18 01:03:06http://1.246.223.4:3402/mozi.mOfflinemirai ext tammeto
2021-10-16 09:23:06http://1.246.223.4:3402/Mozi.aOfflinemirai ext Mozi ext Petras_Simeon
2021-10-03 16:05:05http://1.246.223.4:1447/iOfflinemirai ext Petras_Simeon
2021-04-20 00:49:11http://1.246.223.4:4384/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-04-14 03:34:05http://1.246.223.4:4384/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-02-07 06:20:06http://1.246.223.4:2072/iOfflinebashlite elf gafgyt ext mirai ext zbetcheckin
2020-10-06 04:04:33http://1.246.223.4:1447/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-09-15 11:19:06http://1.246.223.4:1447/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-08-12 10:47:28http://1.246.223.4:2072/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-05-28 03:04:09http://1.246.223.4:2072/Mozi.mOfflinemirai ext Mozi ext Gandylyan1
2020-05-03 09:04:16http://1.246.223.4:1823/Mozi.mOfflinemirai ext Mozi ext Gandylyan1
2020-04-23 15:06:21http://1.246.223.4:2376/Mozi.mOfflineelf mirai ext Mozi ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-03-04 15:49:15e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2023-01-16 11:19:22e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2022-06-15 18:49:07e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2022-05-25 01:04:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2022-04-28 15:49:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-10-18 01:03:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-10-16 09:23:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-10-03 16:05:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-04-20 00:49:11e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-04-14 03:34:05e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2021-02-07 06:20:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-10-06 04:32:04e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-09-15 11:19:06e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-08-12 10:47:28e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-05-28 03:04:09e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-05-03 09:04:16e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai
2020-04-23 15:06:20e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0elfMirai