URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 113.64.250.1
Firstseen:2024-12-31 03:03:04 UTC
Total malware sites :21
Online malware sites :0 (0%)
Offline Malware sites :21 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-31 03:03:35 113.64.250.1Not listedAS4134 CHINANET-BACKBONE- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-22 02:26:27http://113.64.250.1:59565/iOffline32-bit elf mips Mozi ext geenensp
2026-02-22 01:59:07http://113.64.250.1:59565/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-12-19 08:33:14http://113.64.250.1:39780/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-12-17 14:59:13http://113.64.250.1:39780/iOffline32-bit elf mips Mozi ext geenensp
2025-11-26 14:40:43http://113.64.250.1:50589/iOffline32-bit elf mips Mozi ext geenensp
2025-11-26 13:17:14http://113.64.250.1:50589/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-10-20 08:03:19http://113.64.250.1:60871/iOffline32-bit elf mips Mozi ext geenensp
2025-10-20 07:38:07http://113.64.250.1:60871/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-10-08 22:42:20http://113.64.250.1:57748/iOffline32-bit elf mips Mozi ext geenensp
2025-10-08 22:19:26http://113.64.250.1:57748/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-09-28 23:54:20http://113.64.250.1:36806/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-09-26 09:02:28http://113.64.250.1:36806/iOffline32-bit elf Mozi ext threatquery
2025-08-30 03:01:20http://113.64.250.1:45952/iOffline32-bit elf Mozi ext threatquery
2025-08-29 13:42:19http://113.64.250.1:45952/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-07-01 05:56:08http://113.64.250.1:50623/iOffline32-bit elf mips Mozi ext geenensp
2025-07-01 05:34:14http://113.64.250.1:50623/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-04-06 21:45:05http://113.64.250.1:51127/iOffline32-bit elf mips Mozi ext geenensp
2025-04-06 21:25:06http://113.64.250.1:51127/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-02-20 04:48:05http://113.64.250.1:38016/iOffline32-bit elf mips Mozi ext geenensp
2025-02-20 04:17:05http://113.64.250.1:38016/bin.shOffline32-bit elf mips Mozi ext geenensp
2024-12-31 03:03:35http://113.64.250.1:45791/Mozi.mOfflineMozi ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-22 02:26:274293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2026-02-22 01:59:074293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-12-19 08:33:14b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-12-17 14:59:13b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-11-26 14:40:434293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-11-26 13:17:144293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-10-20 08:03:194293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-10-20 07:38:074293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-10-08 22:42:20b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-10-08 22:19:26b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-09-28 23:54:20b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-09-26 09:02:28b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2025-08-30 03:01:204293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-08-30 02:21:234293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-07-01 05:56:084293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-07-01 05:34:144293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-06 21:45:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-06 21:25:064293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-02-20 04:48:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-02-20 04:17:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi