URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 151.243.109.71
Firstseen:2026-01-09 23:10:04 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-09 23:10:06 151.243.109.71Not listedAS209274 Kraken-Network-ISP- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-09 23:17:16http://151.243.109.71/chernobyl.shOfflinegafgyt ext sh ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.mipselOfflineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.arm7Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.arm5Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.i586Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.m68kOfflineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.x86Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.ppcOfflineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:19http://151.243.109.71/chernobyl.sparcOfflineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:16http://151.243.109.71/chernobyl.i486Offlineelf ua-wget NDA0E
2026-01-09 23:11:11http://151.243.109.71/chernobyl.arm6Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:11http://151.243.109.71/chernobyl.arm4Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:11http://151.243.109.71/chernobyl.i686Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:11http://151.243.109.71/chernobyl.mipsOfflineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:11:11http://151.243.109.71/chernobyl.sh4Offlineelf gafgyt ext ua-wget NDA0E
2026-01-09 23:10:06http://151.243.109.71/cacheOfflinegafgyt ext sh ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-09 23:17:156736023d87e29e0e39ff508e27559bbcd42e83302d8de12c4ed2819a18f574abshGafgyt
2026-01-09 23:11:19e87555fdbe81c866fffd83dbd1f8ef715c39c9f6f5199dd492f34d00758e870delfGafgyt
2026-01-09 23:11:19c5f66511b433251e11e10e8c96de228124fe8ca2b42da9ea4ea020d0ac935edfelfGafgyt
2026-01-09 23:11:196e6737a6f981c555ad7561993da55b2652223f0570daa9670ee04b3773e95f12elfGafgyt
2026-01-09 23:11:196b8920b3643b3259df7407e128c29d6b75ac6192f21ced887bd822c62d138596elfGafgyt
2026-01-09 23:11:19502286be2b114959fecd3e9fd30a1e135e68a5eeeff56d5cd483eb78f0fb80b0elfGafgyt
2026-01-09 23:11:19c65bff0cc381e498ec8929fe62a9153c18459cfffa5fd7363c1ba8398e4c80e6elfGafgyt
2026-01-09 23:11:19e799d99fc07cf69e3257c6c9e7d98f42ec7c5d3f39751d302b6793e80fc0d51celfGafgyt
2026-01-09 23:11:19365885c2d2783dd1f09f1cdfc8c5206e406ebac53b1575acaa1c85aaf86a2f76elfGafgyt
2026-01-09 23:11:11bebc03675faaddf5036cb55842b4dad8cd63bd271fd827e17da4e50b6965b843elfGafgyt
2026-01-09 23:11:115aa10ad8ddf32cf939a6ed86b129b96c70c5c85d428692edf2817020b7588326elfGafgyt
2026-01-09 23:11:1130ce7e02ad64d594078d91d50bc6658c3fe31573176161b6b0b7014908cf6348elfGafgyt
2026-01-09 23:11:1178ec72382489fb24c85aaf7febe87c99e8447ccff87df0f03ca3477a0a1af301elfGafgyt
2026-01-09 23:11:111e65db5565160a6cf54239c6459a1c1ba6dc79b415fca206bee9ebafdd65ab70elfGafgyt
2026-01-09 23:10:066736023d87e29e0e39ff508e27559bbcd42e83302d8de12c4ed2819a18f574abshGafgyt