URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 138.201.154.194
Firstseen:2025-08-15 21:02:05 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-15 21:02:14 138.201.154.194static.194.154.201.138.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-16 13:51:21http://138.201.154.194/systemcl/arcOfflineelf ua-wget abuse_ch
2025-08-16 08:19:25http://138.201.154.194/systemcl/x86_64Offlineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:24http://138.201.154.194/systemcl/x86-DEBUGOfflineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:24http://138.201.154.194/systemcl/ppcOfflineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:24http://138.201.154.194/systemcl/arm5Offlineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:17http://138.201.154.194/systemcl/m68kOfflineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:15http://138.201.154.194/systemcl/spcOfflineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:15http://138.201.154.194/systemcl/arm6Offlineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:15http://138.201.154.194/systemcl/arm7Offlineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:11http://138.201.154.194/systemcl/mpslOfflineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-16 08:19:11http://138.201.154.194/systemcl/sh4Offlineelf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-08-15 21:27:12http://138.201.154.194/wget.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-15 21:26:13http://138.201.154.194/c.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-15 21:26:07http://138.201.154.194/test.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-15 21:25:13http://138.201.154.194/w.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-15 21:04:11http://138.201.154.194/systemcl/armOffline32-bit elf mirai ext Mozi ext threatquery
2025-08-15 21:03:11http://138.201.154.194/systemcl/x86Offline32-bit elf mirai ext Mozi ext threatquery
2025-08-15 21:02:14http://138.201.154.194/systemcl/mipsOffline32-bit elf mirai ext Mozi ext threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-19 01:51:407b4acd4f11779c0b1016957bad0cbc77b90e630177aeff6c60c09f86d7b744a2shMirai
2025-08-16 13:00:17b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2elfMirai
2025-08-16 08:19:2547a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230elfMirai
2025-08-16 08:19:21ac768e9ed9afdb7e8075f1324705d5044d20763605e85d6783035142b075f109elfMirai
2025-08-16 08:19:21abfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955eelfMirai
2025-08-16 08:19:21467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecbelfMirai
2025-08-16 08:19:1719abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659elfMirai
2025-08-16 08:19:157a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104elfMirai
2025-08-16 08:19:151745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524elfMirai
2025-08-16 08:19:152b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54celfMirai
2025-08-16 08:19:117365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242elfMirai
2025-08-15 21:27:120d6704f2b8cb547d4ae52ade3409cb9edf35ec282a6b6bbb04f453054efd891ashMirai
2025-08-15 21:26:13f7ed84a0db401c71c87c6adfa25b10533238f06747073cc6b0cd7a7db4366744shMirai
2025-08-15 21:26:071c56ffe87500ec00101d008998df9e93bd0f640c1cb9624ef50a5ba0f112e601shMirai
2025-08-15 21:25:13ec13c1bea8619a3c214187e05bb0d9443b55cfb6f042447d9f7c35b35b126237shMirai
2025-08-15 21:04:11a2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9elfMirai
2025-08-15 21:03:112e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72elfMirai
2025-08-15 21:02:13ad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4elfMirai