URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 158.94.209.95
Firstseen:2025-09-20 12:03:03 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-20 12:03:16 158.94.209.95SBL686264AS214943 RAILNET- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-12 11:30:08http://158.94.209.95/76d32be0.shOfflinemirai ext sh BlinkzSec
2025-10-12 11:30:08http://158.94.209.95/lgOfflinemirai ext sh BlinkzSec
2025-10-12 11:29:08http://158.94.209.95/realtekOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/zyxelOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/goaheadOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/yarnOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/thinkphpOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/pulseOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/zteOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/hnapOfflinemirai ext sh BlinkzSec
2025-10-12 11:28:14http://158.94.209.95/awsOfflinemirai ext sh BlinkzSec
2025-10-12 11:27:15http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext BlinkzSec
2025-09-20 21:31:14http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:49http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:32http://158.94.209.95/x86Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:31http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:27http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:27http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:26http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 16:00:25http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext ua-wget ClearlyNotB
2025-09-20 12:03:16http://158.94.209.95/596a96cc7bf9108cd896f33c44...Offlineelf mirai ext abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-12 11:30:0829fa130eed8854f328b218ef7fde38145c9b1fb9544e85fda781a9f7936f7a81shMirai
2025-10-12 11:30:08dfbce25947a9865310921ae8ebc8d0fd58c4e39b561b3acfd9f4b22ff4084039shMirai
2025-10-12 11:29:08d3ab9f0add06a43680a730a9591e4192b5c855b1427a01374d52562bcfc37d23shMirai
2025-10-12 11:28:14e57509531ccf9d33a996908a1230c0f9552cbb3a307279aab1df6b5acf88b34fshMirai
2025-10-12 11:28:1421c53d2b3ed93dd6cd1afb25ec0e17c001097d36c760cf95d51d26f36f4237aeshMirai
2025-10-12 11:28:1481a5497a004643d1de68c83ac566f995b0c9b57a531503cea13c0666494318eashMirai
2025-10-12 11:28:14b3c32626aaff13b7da383ed178beb92646ba57a215dc16d7467b1a1e3ff8cffbshMirai
2025-10-12 11:28:14e3aa06ff29ac7c834024c92695e16079011cac83537fcf0def3352777df33847shMirai
2025-10-12 11:28:14eee87f46660816bf29a75594272173730a2541c31095dcc3357ed6ff931305ddshMirai
2025-10-12 11:28:147ff10b3508b2978df36801e49f5b63dd6ee7e599269aabcb0d8e478383b83e94shMirai
2025-10-12 11:28:147f74fc7abb1d743042b793d203d6760475e36be0ecdc05ae841bce9e87cf7aceshMirai
2025-10-12 11:27:15e1872b44f151615dd30c9120e8d8bd8d477212b7188a79478af49ff7df6610a9elfMirai
2025-09-20 22:23:22248b6599aebc4e053a68ae502bafc1fec19cc1edcc455a8358e2d3dbe46f0e5eelfMirai
2025-09-20 22:20:21dc06d5d4daab1b23eef11b6eac8da75bafa7e75a7e44d60fb14c9db8199c7553elfMirai
2025-09-20 22:11:16fa94633bd1d61a6bfaad5d6308f4020013ccc11c9c9fa463e9795485b84ddaf5elfMirai
2025-09-20 21:34:276294a0eb4ee65e6ba006a024522658107ec8753f6d3df2dc7309776199da65e7elfMirai
2025-09-20 21:31:1441e5adc3527479d2bee1a3bb4c590899d40713df8fd20e0871a8f2e46a7afeddelfMirai
2025-09-20 21:17:05924b4daa3d183fc7d1312a17b68aa952c8d0136918478730cd95623bb1890ed9elfMirai
2025-09-20 16:00:49cd58c26a61496c5f2091a6e51f6d2764a61073bf619bdd2322be5379b519c71delfMirai
2025-09-20 16:00:319233a833a69028a6d7f4ab16e45f41e24a291935db0ee7556410184b769945f6elfMirai
2025-09-20 16:00:316d65317a9d29fdfee8ff125c78705186155fdb0162f3d13890c43b971bdf6586elfMirai
2025-09-20 16:00:319c08e0232337e3288d21e5f278f98d2a7d514763b85aa5d79c3588e81037ec5delfMirai
2025-09-20 16:00:31924b4daa3d183fc7d1312a17b68aa952c8d0136918478730cd95623bb1890ed9elfMirai
2025-09-20 16:00:314e06ece7ae576417a8dc0e419b8782ce0860cd9e90bc947b4c118e2a52786304elfMirai
2025-09-20 16:00:318ac733a14bdcdf3b2543a8e420d2fa224bc067e425ac38ea9d99fbe389f48c44elfMirai
2025-09-20 16:00:314bd20d49002299fd230f3eeddddcf6bf9e81033d15c8519cdfc296723a57b9d3elfMirai
2025-09-20 12:03:15236fa5092bd06813996532ef793834e31a69ed1e576599eaa97bcf8fb7db9b61elfMirai