URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 103.116.52.207
Firstseen:2024-03-04 11:41:04 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-03-04 11:41:07 103.116.52.207Not listedAS150895 EZTECH-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-27 16:09:10http://103.116.52.207/bot.x86_64Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:10http://103.116.52.207/bot.mipsOfflinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:09http://103.116.52.207/bot.arm7Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:09http://103.116.52.207/bot.arm6Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:09http://103.116.52.207/bot.armOfflinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.arm5Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.ppcOfflinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.m68kOfflinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.sh4Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.mpslOfflinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-08-27 16:09:08http://103.116.52.207/bot.x86Offlinebotnet elf fbi.gov mirai ext moobot Okiru Yakuza NDA0E
2024-04-18 10:14:04http://103.116.52.207/abc1.shOfflineelf moobot shellscript abus3reports
2024-04-18 10:14:04http://103.116.52.207/abc2.shOfflineelf moobot shellscript abus3reports
2024-04-18 10:14:04http://103.116.52.207/abc3.shOfflineelf moobot shellscript abus3reports
2024-03-23 14:20:16http://103.116.52.207/condi.mipsOfflineelf mirai ext ClearlyNotB
2024-03-04 11:41:09http://103.116.52.207/condi.x86_64Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:09http://103.116.52.207/condi.arm7Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:09http://103.116.52.207/condi.armOfflineelf mirai ext moobot abus3reports
2024-03-04 11:41:09http://103.116.52.207/condi.arm6Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:09http://103.116.52.207/condi.m68kOfflineelf mirai ext moobot abus3reports
2024-03-04 11:41:09http://103.116.52.207/condi.arm5Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:08http://103.116.52.207/condi.mpslOfflineelf mirai ext moobot abus3reports
2024-03-04 11:41:07http://103.116.52.207/condi.x86Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:07http://103.116.52.207/condi.sh4Offlineelf mirai ext moobot abus3reports
2024-03-04 11:41:07http://103.116.52.207/condi.ppcOfflineelf mirai ext moobot abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-27 16:09:10abf0e807b58651ec33834e29ba36eea00a335eccf6e0303bb795afb950096e24elfMooBot
2024-08-27 16:09:10298633a8bbc16f5e1ac738b11a13f209e7bc1539c866d45acd117361086c597belfMooBot
2024-08-27 16:09:095842bb3725faaeab8dc1e12c6477dc255f6608982ee2c2a381b045c2b8b620f5elfMooBot
2024-08-27 16:09:09a8874fbcb8629398af2154b8c9aef7eca6450e6f34a2491a40535ca92354a12aelfMooBot
2024-08-27 16:09:09a044889432594aeb91af040823c6daac04329c62a401702ae77a5633707b5985elfMooBot
2024-08-27 16:09:084bf2694b05e3e8435175a952c43c11af6db32067c02e4d06598150e5fffc8862elfMooBot
2024-08-27 16:09:0875f1d02f0167a9fd17321b87214545587ec9ae609f08d938b27e3925071c1127elfMooBot
2024-08-27 16:09:08e1c2c65aa32218028e75032392f0bdf3fa330b1cb2a411bc27717dc539627231elfMooBot
2024-08-27 16:09:082343403a5f968ff7a6c0efe4537f6a976af979e44b1cde116912ae290fcbf7eeelfMooBot
2024-08-27 16:09:08524e2dbf7e949878929e583998ebde3bd1be9fa9b420f936f40ff0313964c6fbelfMooBot
2024-08-27 16:09:07bdf79453fead03d6dc4363b62230c68502e736228ce434a7835bae69393d4261elfMirai
2024-04-18 10:14:04ff394f5a2aed300975e4491c4e4f18ecc42d1ce3f3c36d5b59f1e1de8efecf79unknown  
2024-04-18 10:14:04863d65aafad6032a4af2c4b0880c30a5b09986c11486da3fc20b62c699837e6funknown  
2024-04-18 10:14:04b3516c119f95dbb3c181e7b4ea8d688336600fa882b753a122d59286d986a685unknown  
2024-03-23 14:20:16d4dead285e10536c54e9925a7a7258237e55e333d04b7f31ba19721aa3e2bb95elfMirai
2024-03-04 11:41:09756aaa19767ae0507856a840d6971e6a1c30588f582f43c78585625489dad406elfMirai
2024-03-04 11:41:09608e91d9b5ee60c7798478ff8430575a7b63c33b9c575131405b98beb2edfdd7elfMirai
2024-03-04 11:41:09477ea087bafa03bde51ac19fa6b270a0f475cc46e53745725d658db96ef19d09elfMooBot
2024-03-04 11:41:0949c00a5c6fcf86033db05a5b4580edf063e6ec926653a76c90db4a98d04e6154elfMirai
2024-03-04 11:41:090c358b72e9258da7fd8dd70b33cd8c1b54257e957fb6862f1afc36df504b17e0elfMirai
2024-03-04 11:41:09304abc0ab4790279a9b98b0422b7bd30447a569cd3ef835846fdffc2ef8909caelfMirai
2024-03-04 11:41:08794b5b9fe523941cfd2a279ad4e8093f7709205cf79c1d1aba69dd3ffc2797e3elfMirai
2024-03-04 11:41:07976f28ebeadd1915a3c269b3ebdf44266e3d3be5c79c720614b89f188e0600f6elfMirai
2024-03-04 11:41:071e32f2cb5905ece280e0352a714cfa65ed0d20e018756c532797dd4d46067101elfMirai
2024-03-04 11:41:07488670f83e7579eea23873abf4fb7abab5cc8fa1eff49f0ff150cec1a73b3631elfMirai