URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 103.14.226.21
Firstseen:2024-04-29 06:39:04 UTC
Total malware sites :10
Online malware sites :0 (0%)
Offline Malware sites :10 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-04-29 06:39:39 103.14.226.21Not listedAS149136 AALO-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-05-08 17:22:08http://103.14.226.21/fuckjewishpeople.arm6Offlineelf gafgyt ext tolisec
2024-04-30 02:01:08http://103.14.226.21/bot.arm6Offlineelf mirai ext tolisec
2024-04-30 02:01:08http://103.14.226.21/bot.arm7Offlineelf mirai ext tolisec
2024-04-29 07:34:03http://103.14.226.21/a-r-m-6.SakuraOffline BlinkzSec
2024-04-29 07:13:06http://103.14.226.21/a-r.m-6.SakuraOffline32 arm bashlite elf gafgyt ext zbetcheckin
2024-04-29 06:39:41http://103.14.226.21/m-6.8-k.SakuraOfflineelf gafgyt ext BlinkzSec
2024-04-29 06:39:39http://103.14.226.21/wget.shOfflinemirai ext shell BlinkzSec
2024-04-29 06:39:39http://103.14.226.21/Sakura.shOfflinemirai ext shell BlinkzSec
2024-04-29 06:39:39http://103.14.226.21/c.shOfflinemirai ext shell BlinkzSec
2024-04-29 06:39:39http://103.14.226.21/w.shOfflinemirai ext shell BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-05-08 17:49:4839261013b078230b1aa264b3072fa0c95711210ceeb09590fd6df0da42ad369dunknown  
2024-05-08 17:43:04a5e3653b8414613613d41bde5230af07f712d81ab01e617ad899b2f607bd7357unknown  
2024-05-08 17:22:0811b9a002578b6cded42e148f92093a707276487834c4780b2abb6f4442fa36abelfGafgyt
2024-05-08 17:06:1621fb2953397ef04ec4057766e89bb25d4b7f2625fc99645278f9e9317c521423unknown  
2024-05-07 11:55:131c701fe84f336103c579edaf51c13cf826233c06656ec850da244b07dcc3a9dbunknown  
2024-04-30 02:01:0863fd206023e0a7702e5927b3da888d3f8dc7d5ec026982cd7f46c8db2850928belfMirai
2024-04-30 02:01:0821b4a735e87583c44568f174417157a8ea865c8ade97fe64b7dff6e25b2d66adelfMirai
2024-04-29 21:22:03da903179ec953808cd3c9f481a5f9c48315e45e9c46069b088606ae3f810aa9cunknown  
2024-04-29 21:05:24befca39534fba628d6f129eef4affde4de058eac2d541418c0baf78d41e820c6unknown  
2024-04-29 20:59:41e6799064f7fa2cff3a5e4940b225504fd7a6de5941b534501c78c164764ed60eunknown  
2024-04-29 20:51:20b52e2b06449333b7a575f8d8928c97fcfaced0cea06b4634407b1e81f197d1c9unknown  
2024-04-29 07:24:09c1e7591ae1155ce2f9efabe1c5c3f0a4f4375b60c37a82d0a8033efe81f51210elfGafgyt
2024-04-29 07:19:05cfaa0ff4165048361e9e0de132002b4a2ac9427bf0deab9f71d780e2ac7f4f0bsh  
2024-04-29 07:13:06a161778a196844079d7bb833dd0a7e3dcd6bb37fa5753f4634ed2cadfa7af255elfGafgyt
2024-04-29 07:11:59374a836dcf0c693f3b347574cc83620c17311f68649a1b4b36534f09e96439dfunknown  
2024-04-29 07:07:49156b280892c23cb3c84d51036c48aa10460e16e5b783adc80ea8443d6191079bunknown  
2024-04-29 07:04:23e1313dba7d1ed23759e04a291ada014838fdeb612b827237f6b01e029808761bunknown