URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.216.20.232
Firstseen:2024-08-05 13:47:04 UTC
Total malware sites :46
Online malware sites :0 (0%)
Offline Malware sites :46 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-05 13:47:04 154.216.20.232Not listedAS11404 AS-WAVE-1- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-07 15:39:33http://154.216.20.232/tOfflinemirai ext stopransom
2024-08-07 11:32:09http://154.216.20.232/empslOfflineelf gafgyt ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/earm7Offlineelf mirai ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/earm6Offlineelf mirai ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/emipsOfflineelf gafgyt ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/eppcOfflineelf NDA0E
2024-08-07 11:32:07http://154.216.20.232/earm5Offlineelf mirai ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/earmOfflineelf mirai ext NDA0E
2024-08-07 11:32:07http://154.216.20.232/esh4Offlineelf NDA0E
2024-08-05 13:48:05http://154.216.20.232/bins/arm7Offlineelf mirai ext RacWatchin8872
2024-08-05 13:48:04http://154.216.20.232/mpslOfflineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:48:04http://154.216.20.232/arm5Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:08http://154.216.20.232/bins/mipsOfflineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:47:08http://154.216.20.232/bins/x86Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:08http://154.216.20.232/bins/x86?ddosOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/mipsOfflineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/bins/armOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/bins/arm6Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/bins/arm5Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/arm7Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/armOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:07http://154.216.20.232/arm6Offlineelf mirai ext RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/bins/mpslOfflineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/bins/wget.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/dlr.sh4Offlineascii mirai ext RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/bins/tftp.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/bins/sh4Offlineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:47:06http://154.216.20.232/ppcOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/tftp.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/dlr.armOfflineascii mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/bins/weedOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/dlr.arm7Offlineascii mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/bins/dlr.arm7Offlineascii mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/dlr.ppcOfflineascii mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/dlr.mipsOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/bins/dlr.sh4Offlineascii mirai ext RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/wget.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/weedOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:05http://154.216.20.232/sh4Offlineelf gafgyt ext mirai ext RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/bins/ftpget.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/curl.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/dlr.mpslOfflineelf mirai ext RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/tftp2.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/ftpget.shOfflinebash mirai ext sh RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/bins/dlr.mpslOfflineascii mirai ext RacWatchin8872
2024-08-05 13:47:04http://154.216.20.232/bins/dlr.mipsOfflineascii mirai ext RacWatchin8872

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-08 03:29:56fad1b833149894d19f99ec914464af02016334e4ea2a62a80d50522a33333726elfMirai
2024-08-08 03:25:164183ba9b3c0717d0ea4d737143c337f23e037509a604313ac20247f667628c0celfGafgyt
2024-08-08 03:23:43b7c7a4dee6bed6c4d3c8be8d7cccc6af7f5e33a8eca1ab4a30fe07362ce45793elfGafgyt
2024-08-08 03:14:3842ed4015f32590ae326bf730bc3bf3bb2f7ab7dab82770bf13c19a364b259703elfMirai
2024-08-08 02:23:284cc9e209a0b690434b0f9623c2b6b41cac3b166eea0bd474366fb3d9390c6c61elfGafgyt
2024-08-08 02:09:07ec59972f15c08de1507dc053a46c0dae7565b709af839af5d2b69d2f6d9cb3e0elfMirai
2024-08-08 02:02:40fee4dbe6f0d6b8ea1f8bec922f733161a133b5baaea2f6dd49d9b484eecbf7e1elfMirai
2024-08-07 11:32:090331985724dc711d88b447dd2d352a1b8a9951b045dff4afb2e48895b85c73a7elfGafgyt
2024-08-07 11:32:071500cbdcf6c0c50472336ad9dc3a1d5d00f062b89cc25a758350c4820363455aelfMirai
2024-08-07 11:32:0727c5412cc2036dd7b38f646f090f8b72843aaab3c2ecd70ca8d86665f3d4f1eaelfMirai
2024-08-07 11:32:07d76ad9131500635ddcc945b097160bd38259bf9b77e5d57ee9f408b22f5edf65elf  
2024-08-07 11:32:079dc05db309ba17fa337d56d57b9f5e769f387e654cd69ee54f7771fa0051cf68elf  
2024-08-07 11:32:0779794a133e5820788924f137136348593c481966288a28273df696950c6d543aelfGafgyt
2024-08-07 11:32:072d3482fc6ea845ffe8918e9d186fc8454091b4348feee07006ef7df8752dd6e5elfMirai
2024-08-07 11:32:07efaf599ac65b6960a2888be4b91fdb831ec7bc374d8904794ea837a47af2cd66elfMirai
2024-08-05 13:48:0581b68c0c3656652296c076c4299e2f6adc5f028b8356199b871b6180ba0a4efaelfMirai
2024-08-05 13:48:04b7c7a4dee6bed6c4d3c8be8d7cccc6af7f5e33a8eca1ab4a30fe07362ce45793elfGafgyt
2024-08-05 13:48:04ec59972f15c08de1507dc053a46c0dae7565b709af839af5d2b69d2f6d9cb3e0elfMirai
2024-08-05 13:47:08bf4fb9f0ef0237da5ec130910c69f2c5aeff9a498c11d9b9943639aabaa15b12elfMirai
2024-08-05 13:47:08f52b7e39cfbb72286bc87fb65eebfcc6a07f2630b6ad51887e0c4753dafdbf24elfGafgyt
2024-08-05 13:47:08bf4fb9f0ef0237da5ec130910c69f2c5aeff9a498c11d9b9943639aabaa15b12elfMirai
2024-08-05 13:47:074cc9e209a0b690434b0f9623c2b6b41cac3b166eea0bd474366fb3d9390c6c61elfGafgyt
2024-08-05 13:47:078789153e2848877bf52d6291cc34490dfac43e86ed75de312d0c7712bc8eea48elfMirai
2024-08-05 13:47:071efa24755fa81752df032a1344032ce4a04922d9320afda5e7bdfbf9239811e4elfMirai
2024-08-05 13:47:0707b2d537b42c9a4e10acc47b8912426c0c6a770102c6a418df6f0dba1768dd05elfMirai
2024-08-05 13:47:07fee4dbe6f0d6b8ea1f8bec922f733161a133b5baaea2f6dd49d9b484eecbf7e1elfMirai
2024-08-05 13:47:0742ed4015f32590ae326bf730bc3bf3bb2f7ab7dab82770bf13c19a364b259703elfMirai
2024-08-05 13:47:06fad1b833149894d19f99ec914464af02016334e4ea2a62a80d50522a33333726elfMirai
2024-08-05 13:47:06ebdbd4b16d1c62a538be0491bd67c636ac463d47dc7159c813560be384970931elfGafgyt
2024-08-05 13:47:06e1501dd27b84c3c57238b38b1a547e21b85228335d84c3b68c9e9a4e942e6bafelfGafgyt
2024-08-05 13:47:06b43bef47d26a11bb8b75c0a12813de846f86db8e5502d65481b18680bad74de2elfMirai
2024-08-05 13:47:054183ba9b3c0717d0ea4d737143c337f23e037509a604313ac20247f667628c0celfGafgyt