URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 111.38.106.48
Firstseen:2020-09-13 09:04:02 UTC
Total malware sites :47
Online malware sites :0 (0%)
Offline Malware sites :47 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-13 09:04:16 111.38.106.48Not listedAS9808 CHINAMOBILE-CN- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-14 16:49:13http://111.38.106.48:33469/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-11-20 09:04:34http://111.38.106.48:33469/Mozi.mOfflinemirai ext Mozi ext Gandylyan1
2021-11-13 03:04:05http://111.38.106.48:37306/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-11-01 18:44:13http://111.38.106.48:37306/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-11-01 18:14:07http://111.38.106.48:37306/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-10-29 06:34:06http://111.38.106.48:37306/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-09-07 13:53:04http://111.38.106.48:40260/mozi.mOfflinemirai ext tammeto
2021-09-01 23:18:14http://111.38.106.48:40260/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-09-01 11:32:10http://111.38.106.48:40260/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-08-30 17:50:37http://111.38.106.48:40260/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-08-27 18:49:07http://111.38.106.48:54088/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-08-17 16:39:13http://111.38.106.48:53931/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-08-14 05:49:11http://111.38.106.48:53931/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-08-12 23:28:05http://111.38.106.48:53931/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-07-31 01:04:09http://111.38.106.48:48575/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-07-20 23:04:41http://111.38.106.48:48575/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-07-04 17:19:13http://111.38.106.48:59004/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-06-20 14:00:08http://111.38.106.48:59004/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-06-20 13:33:13http://111.38.106.48:59004/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-06-15 02:19:15http://111.38.106.48:59004/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-05-28 19:58:05http://111.38.106.48:50067/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-05-25 15:19:10http://111.38.106.48:38026/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-05-19 22:19:13http://111.38.106.48:38026/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-05-19 21:49:11http://111.38.106.48:38026/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-05-17 00:34:29http://111.38.106.48:38026/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-05-08 18:18:17http://111.38.106.48:50322/bin.shOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-05-07 22:05:15http://111.38.106.48:50322/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-05-06 18:05:09http://111.38.106.48:50322/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-05-05 10:58:09http://111.38.106.48:50322/iOffline32-bit arm elf mirai ext Mozi ext geenensp
2021-03-27 00:30:05http://111.38.106.48:55238/bin.shOffline32-bit arm elf mirai ext geenensp
2021-03-24 00:13:05http://111.38.106.48:55238/iOffline32-bit arm elf mirai ext geenensp
2021-03-13 06:04:07http://111.38.106.48:55238/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-03-05 17:04:06http://111.38.106.48:55238/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2021-01-03 21:04:06http://111.38.106.48:57044/Mozi.mOfflinemirai ext Mozi ext Gandylyan1
2020-12-23 00:49:04http://111.38.106.48:35958/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-22 02:19:04http://111.38.106.48:57131/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-13 09:19:13http://111.38.106.48:55768/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-12-11 11:34:05http://111.38.106.48:39016/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-06 22:34:05http://111.38.106.48:45930/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-12-01 21:19:05http://111.38.106.48:48025/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-11-23 19:04:09http://111.38.106.48:55911/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-11-21 10:49:07http://111.38.106.48:48463/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-11-20 10:49:05http://111.38.106.48:48463/Mozi.aOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-10-10 21:01:04http://111.38.106.48:56257/iOffline32-bit arm elf mirai ext geenensp
2020-10-10 20:32:05http://111.38.106.48:56257/bin.shOffline32-bit arm elf mirai ext geenensp
2020-09-21 01:50:08http://111.38.106.48:56257/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus
2020-09-13 09:04:16http://111.38.106.48:39563/Mozi.mOfflineelf mirai ext Mozi ext lrz_urlhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-14 16:49:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-11-20 09:26:3512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-11-13 03:04:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-11-01 18:44:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-11-01 18:14:0712013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-10-29 06:34:0612013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-09-07 13:53:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-09-01 23:18:1412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-09-01 11:32:1012013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-08-30 18:11:3612013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-08-27 18:49:0712013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-08-17 16:39:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-08-14 05:49:1112013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-08-12 23:28:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-07-31 01:04:0912013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-07-21 18:01:2412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-07-04 17:19:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-06-20 14:00:0812013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-06-20 13:33:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-06-15 02:19:1512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-28 19:58:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-25 15:19:1012013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-19 22:19:1312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-19 21:49:1112013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-17 00:34:2912013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-08 18:18:1712013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-07 22:05:1512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-06 18:05:0912013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-05-05 10:58:0912013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-03-27 00:30:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-03-24 00:13:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-03-13 06:04:0612013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-03-05 17:04:0612013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-01-03 21:04:0612013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-23 00:49:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-22 02:19:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-11 11:34:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-06 22:34:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-01 21:19:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-11-23 19:04:0912013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-11-21 10:49:0712013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-11-20 10:49:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-10-10 21:01:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-10-10 20:32:0512013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-09-21 01:50:0812013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-09-13 09:04:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai