URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 103.91.245.60
Firstseen:2020-09-29 20:34:02 UTC
Total malware sites :31
Online malware sites :0 (0%)
Offline Malware sites :31 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-29 20:34:08 103.91.245.60Not listedAS140641 YOTTA- INyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-11-27 14:52:10http://103.91.245.60:36498/Mozi.aOfflineMozi ext Petras_Simeon
2021-11-22 12:16:06http://103.91.245.60:49231/mozi.aOffline tammeto
2021-11-19 12:11:04http://103.91.245.60:43888/mozi.aOffline tammeto
2021-11-19 12:04:05http://103.91.245.60:49231/Mozi.mOfflineMozi ext Gandylyan1
2021-11-18 05:56:05http://103.91.245.60:55276/mozi.mOffline tammeto
2021-11-11 20:49:06http://103.91.245.60:60346/mozi.mOffline tammeto
2021-11-04 02:12:06http://103.91.245.60:46650/mozi.aOffline tammeto
2021-11-02 17:48:03http://103.91.245.60:53677/mozi.aOffline tammeto
2021-11-01 00:37:04http://103.91.245.60:46650/mozi.mOffline tammeto
2021-10-31 16:23:03http://103.91.245.60:36724/mozi.mOffline tammeto
2021-07-25 12:03:04http://103.91.245.60:48930/Mozi.mOfflineMozi ext Gandylyan1
2021-07-13 15:49:20http://103.91.245.60:40268/Mozi.mOfflineelf Mozi ext Petras_Simeon
2021-05-16 12:03:11http://103.91.245.60:38624/Mozi.mOfflineMozi ext Gandylyan1
2020-12-09 18:34:06http://103.91.245.60:54236/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-12-05 08:19:09http://103.91.245.60:36987/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-11-27 13:19:07http://103.91.245.60:37738/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-11-06 22:40:34http://103.91.245.60:48154/bin.shOffline32-bit elf mips geenensp
2020-11-06 02:19:09http://103.91.245.60:45721/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-11-04 05:25:09http://103.91.245.60:36382/iOffline32-bit elf mips geenensp
2020-11-03 11:04:15http://103.91.245.60:36382/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-11-03 03:04:11http://103.91.245.60:36382/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-10-23 10:34:07http://103.91.245.60:48615/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-23 06:19:07http://103.91.245.60:36141/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-22 23:34:09http://103.91.245.60:36987/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-20 12:04:07http://103.91.245.60:32846/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-16 20:04:07http://103.91.245.60:48154/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-10-16 11:43:38http://103.91.245.60:48154/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-03 20:49:06http://103.91.245.60:56113/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-03 11:34:09http://103.91.245.60:56113/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-10-02 03:04:18http://103.91.245.60:59263/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-09-29 20:34:08http://103.91.245.60:50203/Mozi.mOfflineelf Mozi ext lrz_urlhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-12-09 18:34:06c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-12-05 08:19:09c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-27 13:19:07c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-06 23:00:32c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-06 02:30:23c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-04 05:25:09c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-03 11:04:15c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-11-03 03:04:11c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-23 10:34:07c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-23 06:19:07c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-22 23:34:09c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-20 12:04:07c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-16 20:04:07c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-16 11:43:38c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-03 20:49:06c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-03 11:34:09c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-10-02 03:04:18c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-29 20:34:08c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf