URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 14.138.109.129
Firstseen:2021-01-11 15:35:23 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-15 06:20:07 14.138.109.129Not listedAS9943 KNCTV-AS- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-08-03 18:20:07http://14.138.109.129:3236/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-07-31 17:37:18http://14.138.109.129:3236/iOffline32-bit elf mips Mozi ext geenensp
2023-07-07 03:12:07http://14.138.109.129:3913/iOffline32-bit elf mips Mozi ext geenensp
2023-06-30 18:59:33http://14.138.109.129:3913/bin.shOffline32-bit elf mips Mozi ext geenensp
2023-06-21 06:04:27http://14.138.109.129:2563/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-06-14 13:59:23http://14.138.109.129:2563/iOffline32-bit elf mips Mozi ext geenensp
2023-06-14 13:31:22http://14.138.109.129:2563/bin.shOffline32-bit elf mips Mozi ext geenensp
2023-05-29 03:04:13http://14.138.109.129:4558/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-05-27 21:54:18http://14.138.109.129:4032/iOffline32-bit elf mips Mozi ext geenensp
2023-05-26 04:40:22http://14.138.109.129:4032/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-05-22 00:17:22http://14.138.109.129:4032/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-03-20 08:51:10http://14.138.109.129:3763/iOffline32-bit elf mips Mozi ext geenensp
2022-03-20 08:23:08http://14.138.109.129:3763/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-03-16 00:49:06http://14.138.109.129:3763/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2021-11-01 06:35:06http://14.138.109.129:3767/bin.shOffline32-bit elf mips Mozi ext geenensp
2021-10-31 18:20:06http://14.138.109.129:3767/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2021-10-30 20:20:11http://14.138.109.129:3767/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2021-10-29 10:21:12http://14.138.109.129:3767/iOffline32-bit elf mips Mozi ext geenensp
2021-07-18 02:03:12http://14.138.109.129:2834/iOffline32-bit elf mips Mozi ext geenensp
2021-07-18 01:00:05http://14.138.109.129:2834/bin.shOffline32-bit elf mips Mozi ext geenensp
2021-07-05 08:51:11http://14.138.109.129:2834/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2021-05-10 17:11:19http://14.138.109.129:4164/iOffline32-bit elf mips Mozi ext geenensp
2021-05-10 16:40:15http://14.138.109.129:4164/bin.shOffline32-bit elf mips Mozi ext geenensp
2021-05-10 14:23:11http://14.138.109.129:4164/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-27 03:35:07http://14.138.109.129:3913/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-15 06:20:07http://14.138.109.129:2937/Mozi.mOfflineelf Mozi ext lrz_urlhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-08-03 18:20:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-07-31 18:43:4884c6efae14892f34461cf21f3e6c6d749efb421ca65cecf1e23df5a6baf2d96belf  
2023-07-31 17:37:18f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-07-07 03:12:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-07-02 04:48:26f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-21 06:04:27f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-14 13:59:23f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-14 13:31:22f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-29 03:04:13f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-27 21:54:18f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-26 04:40:22f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-22 00:17:22f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-03-20 08:51:10f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-03-20 08:23:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-03-16 00:49:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-11-01 06:35:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-10-31 18:20:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-10-30 20:20:11f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-10-29 10:21:12f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-07-18 02:03:12f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-07-18 01:00:05f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-07-05 08:51:11f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-05-10 17:11:19f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-05-10 16:40:15f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2021-05-10 14:23:11f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-10-27 03:35:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-10-15 06:20:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf