URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.6.197.44
Firstseen:2025-11-22 16:33:05 UTC
Total malware sites :17
Online malware sites :13 (76%)
Offline Malware sites :4 (24%)
Newest active malware site :2025-11-22 16:33:14 UTC
Oldest active malware site :2025-11-22 16:33:14 UTC (Age: 21 hours, 25 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-22 16:33:13 154.6.197.44mail-wm1-f44.freeads.nlNot listedAS395880 BCL-AS1- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-23 07:50:11http://154.6.197.44/bin/Polar.i468Offlineelf ua-wget abuse_ch
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.arcOfflinearc elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.arm7Onlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.m68kOnlineelf geofenced m68k mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.i686Onlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.spcOnlineelf geofenced mirai ext opendir sparc ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.mpslOnlineelf geofenced mips mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/debugOfflineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.arm6Onlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/qkuys.shOfflinegeofenced mirai ext opendir sh ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.sh4Onlineelf geofenced mirai ext opendir SuperH ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.x86Onlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.armOnlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.ppcOnlineelf geofenced mirai ext opendir PowerPC ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.mipsOnlineelf geofenced mips mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.arm5Onlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-11-22 16:33:14http://154.6.197.44/bin/Polar.x86_64Onlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-22 16:33:1493a1c252d10d76024a5d488f92658d0f9cd32dc0ad90ed9ed64b26bcb93194caelfMirai
2025-11-22 16:33:143ab21df5266014a5d499a423818b1ecce0ed014d99cb2670e582b2449a1d9789elfMirai
2025-11-22 16:33:14ed92383ba83cf87045d54e5235418a73b279258abe9c1ad0c00c093ce42da7aaelfMirai
2025-11-22 16:33:14721fe15d7d32f9940823b6401dba7004634d31e5d0144e778e07fd24d266d0f1elfMirai
2025-11-22 16:33:14823e092401f287b3e22f10869327f39323375a93542880b8680371be1e1d9b3aelfMirai
2025-11-22 16:33:14acc9ea729fb577311870758f13e08f838e1e658d3fcf1046682667331426f223elfMirai
2025-11-22 16:33:143bbb478c8b9d843bfac8b3e30c1a8995c8083c9bec566afb0a8cc83f0152a855elfMirai
2025-11-22 16:33:144fe7c8ec1c0bc38038cd295f0e86e4ee82a6acfacf078216dca3ec934b9a9419elfMirai
2025-11-22 16:33:133913c5e5e2c0324d51da1c172928b0d32e8dbbecae4f180b4f0ab643afcbd389shMirai
2025-11-22 16:33:13d5f6fe226289a3f9cb5d83db63a2fdbf0024f61ac7b893b670129813e9fa0a08elfMirai
2025-11-22 16:33:13ee9753ac80e2def70e03baeab0451978552c4705ff035fa4e674bb40a3ccaa91elfMirai
2025-11-22 16:33:1359c55501918e0f7c6c0fbdfb9582b3bd2cb851d56608bbe4cfd76eb5225bed7felfMirai
2025-11-22 16:33:135f4e153c8107eba841c35ec284550fef6f37149f5e340f8c93a51de95eeb368felfMirai
2025-11-22 16:33:13583901d5241b61add64f1c5a4b0db6f208e1966b59f875c6b752c9ba1a97f2aaelfMirai
2025-11-22 16:33:1331089c8a5283bb413a4d4baf0465cc0865bd741ec5243fa42c9e4a0b1e8b23a8elfMirai
2025-11-22 16:33:13e4887d3bd2122919343f1cd0d222deb98f1a652fceb4dc4746cef8a64ac84266elfMirai