URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 122.199.79.41
Firstseen:2021-01-29 12:04:18 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-01-29 12:04:49 122.199.79.41Not listedAS9981 SAERONET-AS-KR- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-01-29 12:04:49http://122.199.79.41:2775/Mozi.mOfflineMozi ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-30 09:32:088faab2a11062162a0522cf6bd29f8663e9aaeb655c3840deb5a0557130e8b8afelf  
2021-01-30 06:52:00eeac815a3ace597284c0485efd570ad93ae319c9c15df27488c4a0b15bfec851elf  
2021-01-30 03:48:45ca70cadb51f8237c86afaa0c446cb411f8c01bd8a1f78feddbc1fc802ee67f68elf  
2021-01-30 01:05:57b04b08b1da7fb9246b69030377339b4bd9c0bc6f3b8c8d1b218039684ac5d1eeelf  
2021-01-30 00:40:30403f689d3db465b222bf570e0869400c8d17c0a98f4a18f08bdf51480e860fc4elf  
2021-01-29 13:11:13f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf