URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 108.136.241.40
Firstseen:2025-12-06 19:21:04 UTC
Total malware sites :22
Online malware sites :0 (0%)
Offline Malware sites :22 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-06 19:21:11 108.136.241.40ec2-108-136-241-40.ap-southeast-3.compute.amazonaws.comNot listedAS16509 AMAZON-02- IDyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-06 19:22:09http://108.136.241.40/x-3.2-.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:13http://108.136.241.40/bins/bot.x86Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:12http://108.136.241.40/m-6.8-k.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:12http://108.136.241.40/bins/bot.powerpcOfflinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:12http://108.136.241.40/bins/bot.x86_64Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:12http://108.136.241.40/bins/bot.mipsOfflinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:12http://108.136.241.40/a-r.m-4.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/bins/bot.arm7Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/bins/bot.arm6Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/p-p.c-.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/a-r.m-7.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/s-h.4-.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/bins/bot.mipselOfflinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/m-p.s-l.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/m-i.p-s.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/a-r.m-6.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/bins/bot.arm4Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/Sakura.shOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/x-8.6-.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/bins/bot.arm5Offlinemirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/a-r.m-5.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-06 19:21:11http://108.136.241.40/i-5.8-6.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-06 19:22:083631b17e11c957f5817773d55d2b6bb17be668252648728ce2c392ce2d90755delfGafgyt
2025-12-06 19:21:135e107abdecbe1841e09e984378c2af3a25dcdfd1247f21462e155346fa13f2a2elfMirai
2025-12-06 19:21:12271fcd3c47cc6c1ffdedf78bed72983e193d0072fd6eeb9b6e57945a5a0034a8elfGafgyt
2025-12-06 19:21:12cf45d16b7937490e602c619aa8ea9e1b2f4eddddc7c9c61c0e8936513d45c0e5elfMirai
2025-12-06 19:21:12ded5f58c22030487d88c76a96bb35ab4aecb2ff63b41c3e0ff48e7cba1cbe4caelfMirai
2025-12-06 19:21:1116258383a4e5e2d186076e18433189e0576df269c7ab17f5f8f1c30bb86f62a1elfMirai
2025-12-06 19:21:11c685707c97ef7926f1bfdcfba2c9aa89e8114b936fd33c7b14d60385c681da55elfMirai
2025-12-06 19:21:11800765492fdb6e8c32c45872c83b24cf9b783f1d89253a764df4e72c47957ceaelfGafgyt
2025-12-06 19:21:11c97c37addc3bf3f359472190e4eec9b464819462cd1abe832dd96b80db216676elfMirai
2025-12-06 19:21:11800765492fdb6e8c32c45872c83b24cf9b783f1d89253a764df4e72c47957ceaelfGafgyt
2025-12-06 19:21:112cba2be6712fadce3c5cea9e12ba5187be3f59e52f684d2e8ab9c178e587636aelfGafgyt
2025-12-06 19:21:114d6b4e747cc13d9ed89873736d6c69772389b8d13448ec6493d62312295dafe3elfGafgyt
2025-12-06 19:21:11578a7d4b2c923fd355b0dde87b33cfc71798b0116a42f6413a0a61bb5b7b28eeelfMirai
2025-12-06 19:21:112d49b935c8be0b3436b9afda72f8b61736e8245b62d4047d25f75f27c39a7249elfGafgyt
2025-12-06 19:21:11f2bd4a9ed8666dc4a1c7b0baa5cce122fad87ad915e6f4052fcaab678611ef31elfGafgyt
2025-12-06 19:21:11288e6fc449440a9246db99f3713560c1f07f3f2af706116b956c4f3375b16221elfGafgyt
2025-12-06 19:21:116d7ce9013b1bf3ee2bd435541c3eb8a633ef1d694994bda82e2b1ff76a89a8eaelfMirai
2025-12-06 19:21:11144272513db4722f1bcd187881543c19aeec77be4c5ab40dda7ee96f710a1187shGafgyt
2025-12-06 19:21:11c5928679dd8a4cc007d2155284d8a03f3d2005fc652edfec55545131822bf424elfGafgyt
2025-12-06 19:21:1115c213842cc5a9f5f74d18d066085204f7f07f630785b1b7d1d02cebccc0a956elfMirai
2025-12-06 19:21:1119c840622d92b3183641974a87ddb0d25129c8b017b354d591b1bd3fde1b0f31elfGafgyt
2025-12-06 19:21:1137fb3b56f920f1885091d45aded5b0dcfa74360fd760062f0c1df98d8047746aelfGafgyt