URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 103.43.18.19
Firstseen:2024-10-17 14:19:04 UTC
Total malware sites :19
Online malware sites :1 (5%)
Offline Malware sites :18 (95%)
Newest active malware site :2025-08-05 21:02:17 UTC
Oldest active malware site :2025-08-05 21:02:17 UTC (Age: 5 months, 10 days, 11 hours, 14 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-10-17 14:19:18 103.43.18.19SBL274761AS132883 TOPWAY-AS-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-05 21:02:25http://103.43.18.19:16788/https-230.exeOfflineMetasploit ua-wget BlinkzSec
2025-08-05 21:02:23http://103.43.18.19:16788/armOfflineua-wget BlinkzSec
2025-08-05 21:02:22http://103.43.18.19:16788/amd64OfflineSliver supershell ua-wget BlinkzSec
2025-08-05 21:02:18http://103.43.18.19:16788/ver.exeOfflineua-wget BlinkzSec
2025-08-05 21:02:17http://103.43.18.19:16788/yiOnlinesupershell ua-wget BlinkzSec
2025-08-05 21:02:16http://103.43.18.19:16788/arm64Offlineua-wget BlinkzSec
2025-08-05 21:02:14http://103.43.18.19:16788/serverOfflineua-wget BlinkzSec
2025-08-05 21:02:06http://103.43.18.19:16788/x86.binOfflineua-wget BlinkzSec
2025-08-05 21:02:06http://103.43.18.19:16788/x64.binOfflineua-wget BlinkzSec
2025-08-05 21:02:06http://103.43.18.19:16788/server.exeOfflineua-wget BlinkzSec
2025-08-05 21:02:06http://103.43.18.19:16788/yi.shOfflinesupershell ua-wget BlinkzSec
2025-08-05 20:43:04http://103.43.18.19:16788/aaa.shOfflineConnectBack ua-wget BlinkzSec
2025-08-05 20:42:06http://103.43.18.19:16788/mshellOfflineConnectBack ua-wget BlinkzSec
2024-11-07 15:22:12http://103.43.18.19:88/svchost.rarOfflineexe Riordz
2024-11-07 15:22:09http://103.43.18.19:88/hfs.exeOfflineexe Riordz
2024-11-07 15:22:08http://103.43.18.19:88/https.exeOfflineexe Metasploit Riordz
2024-11-07 15:22:07http://103.43.18.19:88/x64.binOfflineexe Riordz
2024-11-07 15:22:06http://103.43.18.19:88/x86.binOfflineexe Riordz
2024-10-17 14:19:18http://103.43.18.19:88/666.exeOfflineexe trojan Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-12 08:04:07e09f66978e94f4eb3c379f58de9ea6e3e9808fa5daaaf4764e441f74e14ef147elfSliver
2026-01-12 02:29:22200c3fe53bcf48ac25dcf0c4fe111180b3849049a1f8f15b0269f2beb8ad49d1elf 
2026-01-12 01:19:59968521cfb36aed34e85ff61bd158ee22fdc1dc6e22b86fb0d0ebacdbdc7b194celf 
2025-08-05 21:02:252c23ebfdae563e676de0f80ed5277ef022dcf6b8d1a6c612162d182658ba628dexeMetasploit
2025-08-05 21:02:239ef72853b140a7f28678058bf2f453f8acab845d98365639ab382323bba29dbcelf 
2025-08-05 21:02:22aeb03a96d67835d33c2abb204b5401f69dae294f2c2a3fdd5338c6ae62d7ba53elfSupershell
2025-08-05 21:02:18f4ea99dc41cb7922d01955eef9303ec3a24b88c3318138855346de1e830ed09eexe  
2025-08-05 21:02:17eb8c12e9b881357c912d6e75f85e87842ac4859e183d97e0af24bd3fe945e895elfSupershell
2025-08-05 21:02:16872a88b567d2f5d0cdd5c6d8c07f2d82174690dd055dedfc6e55c6524bfb5639elf 
2025-08-05 21:02:1418698365a4ba96d1a918f61b988291fc9eed80615518a72826b0bb92c6c90a06elf 
2025-08-05 21:02:066940302ab3a5d539dabd5a53cc0846f9aba350ed0a2afb64626a6030d8b9732eelf  
2025-08-05 21:02:06d01d9666a919df9bb3cd04273ddb27a9da4bd4e312191afc94110f2ed7b7fcd8exe 
2025-08-05 21:02:06e4b0d2775f8a683210926ea49f8a0f63a017205268f49d7aca667e5c86130a7eelf  
2025-08-05 21:02:0526efebddb42aa2f169d9ee3db047a025ba43524b923d368cd2923524f9f7a6b1shSupershell
2025-08-05 20:43:04e359935af4f7bc74ecb302eb7c49978c5e1c822d86f55c115cb99af12d09d4fashConnectBack
2025-08-05 20:42:0683292aeef70102ce9350de34fbb6be40a2eb17aa4f3b9a30322ae8f208c79e44elfConnectBack
2024-11-07 15:22:12924e25bd47f4307a61ba7e9e6eeb10183975b3c978b8279fb729066920bc7573rar  
2024-11-07 15:22:09e678899d7ea9702184167b56655f91a69f8a0bdc9df65612762252c053c2cd7cexe  
2024-11-07 15:22:07c2b8512055bcd2b94f235a56c6add1914d92a2fc78c5cb7c942d3c4496263a68exeMetasploit
2024-11-07 15:22:076940302ab3a5d539dabd5a53cc0846f9aba350ed0a2afb64626a6030d8b9732eelf  
2024-11-07 15:22:06e4b0d2775f8a683210926ea49f8a0f63a017205268f49d7aca667e5c86130a7eelf  
2024-10-17 14:19:089d1c23ccb738f203000152d93334e6b84af277094a735b009e268dd95623b77cexe