URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.216.18.27
Firstseen:2024-11-14 21:44:04 UTC
Total malware sites :34
Online malware sites :0 (0%)
Offline Malware sites :34 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-11-14 21:44:04 154.216.18.27Not listedAS11404 AS-WAVE-1- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-30 01:11:44http://154.216.18.27/arm5Offlineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:41http://154.216.18.27/armOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:37http://154.216.18.27/spcOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:36http://154.216.18.27/x86Offlineelf gafgyt ext mirai ext ua-wget ClearlyNotB
2024-12-30 01:11:34http://154.216.18.27/sh4Offlineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:34http://154.216.18.27/m68kOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:31http://154.216.18.27/arm6Offlineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:27http://154.216.18.27/mipsOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:26http://154.216.18.27/ppcOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:20http://154.216.18.27/mpslOfflineelf gafgyt ext ua-wget ClearlyNotB
2024-12-30 01:11:14http://154.216.18.27/arm7Offlineelf gafgyt ext ua-wget ClearlyNotB
2024-11-14 21:47:04http://154.216.18.27/dlr/dlr.m68kOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:46:05http://154.216.18.27/dlr/dlr.arm7Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:45:07http://154.216.18.27/dlr/dlr.armOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:45:07http://154.216.18.27/dlr/dlr.arm5Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:45:07http://154.216.18.27/dlr/dlr.mpslOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:45:07http://154.216.18.27/dlr/dlr.ppcOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.sh4Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/dlr/dlr.x86Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/dlr/dlr.mipsOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/dlr/dlr.sh4Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/dlr/dlr.arm6Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/dlr/dlr.spcOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.arm6Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.mipsOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.arm5Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.x86Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.m68kOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.armOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.spcOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.arm7Offlineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.ppcOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:07http://154.216.18.27/bins/byte.mpslOfflineelf mirai ext ua-wget DaveLikesMalwre
2024-11-14 21:44:04http://154.216.18.27/hik.shOfflinemirai ext sh ua-wget DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-01-01 16:30:063f60481e7ddd23e3a20cff5930710474591bf3b68eb0d6d35fc96ad698156496elfGafgyt
2025-01-01 16:29:4116004372820eae214bf98ce210a666ba26eb6553891d20c2eb901bf2fbe60747elfGafgyt
2025-01-01 16:02:115585626d556664314cc620db3abda437bc00c32e603357f07bb2f10a3f24a412elfGafgyt
2025-01-01 15:26:248ab10e1c2249a8494950550b03a29c4c847050d10d3698cefd8daf7beca0076celfGafgyt
2025-01-01 15:26:14d0451a1ee27496f6ec3608593e77da1e0102fc54ce89427ae03629a10a0dbfb8elfGafgyt
2025-01-01 15:14:05c486d29f55a93d311b2bb937ec377d5d2538359b64332560cfd9b3442d636a95elfMirai
2025-01-01 14:56:30afa43fbfa98c375116fb4606113a04012b0b88e3c7a594a252180b0fcd1c1c50elfGafgyt
2025-01-01 14:51:35aa712c166dbefaf7c84f1c679b71fe37eaf35d7aea8d3fca339613d67df48e70elfGafgyt
2025-01-01 14:51:22bf82b79ca4803adef7ce4d2456d6d3adb04a867fedebd07de87feeb8d5761e11elfGafgyt
2025-01-01 14:51:217dff99bfd77e478c46ad32ef9082fa235a548d7abe1d34186f178b95123a592aelfGafgyt
2025-01-01 14:48:18e4358a36b86d1a3d34167ae17f83d642eabab3a936ea2fecec04dc724ccd1c3belfGafgyt
2024-12-30 01:11:44abdbb122771ebfc211f8ea24b5c009923e5b0028bfad001d740cbd4ea3b79ca0elfGafgyt
2024-12-30 01:11:401b44454ddbab75b15db0a00ea6c26878732eda93ffb648cd9db334e80c249308elfGafgyt
2024-12-30 01:11:37df45feb29996518c5b50c2aad7ad61a089f75dc91a1d453117b4dc0d9942eb2felfGafgyt
2024-12-30 01:11:363ea72cb22a6f75a513d5fdf81bd054ac24639023b37b0229ecbbb6343bfcf366elfGafgyt
2024-12-30 01:11:342da1fc9acf98e44dbfa39976cfd44e686dbfeb3e9440b2391f5a5d19f3b5bc58elfGafgyt
2024-12-30 01:11:3412bf9b24b706c12de76c12521b7a25b3373d282a36a97a94f4d811d04340f10felfGafgyt
2024-12-30 01:11:30e5364f3baf34c9911eed614ca6c35fc032c854efb6c5ce45b2fc82b9c250cf53elfGafgyt
2024-12-30 01:11:26fa15665c6bf6fe55b2f10da21589d7be0b531bc0a0de1e1110c3621d8f93509aelfGafgyt
2024-12-30 01:11:25f93ef9fa52efcf0f438767ec7db0bf85490a9c282dbfa4d76c56d0061368ab7celfGafgyt
2024-12-30 01:11:20e56601764d0e0613cd34dfb1fd57bdcdf59ec7fa0ccb1c5fe61b3f81efd05dbcelfGafgyt
2024-12-30 01:11:14b5f7265ab3e9c1189cace3f86d6fefc159964a7e4f0835452adca7b2172d4af6elfGafgyt
2024-11-14 21:47:045cea0e2f93b963c06edde75c84562e8738fa37f3894385c63edbd4c19e407bb9elfMirai
2024-11-14 21:46:050a7d443b249975b9290e340c818f2d66b4592482a10ac746cbf17cc175f5e815elfMirai
2024-11-14 21:45:078fdc1b9e469b6927ab76f1910d4d01f95154b13d5d3fb80de2f11a8a732f9d53elfMirai
2024-11-14 21:45:0737af77f7a68281ee447229b93af9848df6a1f428438b8008db561411bfcc4aa5elfMirai
2024-11-14 21:45:07a294624904b308bedf1c0497c411a28fc45d89f67c8c1017801121b847bf778belfMirai
2024-11-14 21:45:0711ca65fa85fe6de457d31a732fd2234f1be455b36c96c0a5a5d3f4db8e063003elfMirai
2024-11-14 21:44:07412661a317a946a2aca23d7ac4ae9c0bdca63d843dbc5d126b79afb9c56426faelfMirai
2024-11-14 21:44:07180632c85d78d71b08d1695d1e335077a987a8cccae000624a5103f83390aa37elfMirai
2024-11-14 21:44:073011d55e1b36e363169dd7a36e95f11d7451d2170daf9b7bf2fa9b6c1aae7eabelfMirai
2024-11-14 21:44:07c87c43ffbe1736452c78e856544d12e2c0a32872b733ad8bd7ffeee98c1e19a7elfMirai
2024-11-14 21:44:07124b3d90bd3a5b90302a0dc5d861173f7163aa856d8eaa3f839fb841a808e13belfMirai
2024-11-14 21:44:07509a1343fab6dc704c0cb805284df2c7bd17194c487d250dfb9d6291561f981aelfMirai
2024-11-14 21:44:07a1badb5317009fe55702c638b0c5816a92337e855e83db12e99e721db7b193c3elfMirai
2024-11-14 21:44:0723e0e50669e47ab61c17e46edfe6fe79b0917a1e840d49abdfc434207522fa7felfMirai
2024-11-14 21:44:07c6ae73632bd6fa5d687fff20eb717d3e0a59a0b6c368a41485fcf925ed455173elfMirai
2024-11-14 21:44:07537907609ffc903d04b1aa5309d9bd02b95a31f343763ae83cd61f9c1b797438elfMirai
2024-11-14 21:44:078dba9862985bd9a2cf54d1cb1487df258259550a6671e3d7b2fbac2274dee5a2elfMirai
2024-11-14 21:44:07d60130d48610638895e18f2994a264cd7fbb0560c7b2f552fc1715f4dfed30e5elfMirai
2024-11-14 21:44:071e6bbf550d9d25d36dce69b46e2086dac0137136eb4b82224110114e2fbbe7ceelfMirai
2024-11-14 21:44:07794fa0280e56a929306cc43b10b1c9f191265868a8fbc3a1ed3f5a905fb65cebelfMirai
2024-11-14 21:44:0729f04ee8c6e0b37540295a239d95be6d88c6ca8b295d91370ad4603d19a24eb8elfMirai
2024-11-14 21:44:07e35a1943ed7c2e95bb119671722cb8ea3d51810fe73a7e6950a4c8f3b8bdad33elfMirai