URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 16.171.16.1 |
|---|---|
| Firstseen: | 2026-06-10 05:39:04 UTC |
| Total malware sites : | 11 |
| Online malware sites : | 1 (9%) |
| Offline Malware sites : | 10 (91%) |
| Newest active malware site : | 2026-06-10 06:27:26 UTC |
| Oldest active malware site : | 2026-06-10 06:27:26 UTC (Age: 14 hours, 48 minutes) |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-06-10 05:39:05 | 16.171.16.1 | ec2-16-171-16-1.eu-north-1.compute.amazonaws.com | Not listed | AS16509 AMAZON-02 | SE | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2026-06-10 06:28:19 | http://16.171.16.1/x86_64 | Offline | 16-171-16-1 DDoSAgent elf ua-wget | |
| 2026-06-10 06:27:27 | http://16.171.16.1/x86 | Offline | 16-171-16-1 elf mirai | |
| 2026-06-10 06:27:27 | http://16.171.16.1/ppc64 | Offline | 16-171-16-1 elf ua-wget | |
| 2026-06-10 06:27:27 | http://16.171.16.1/armv7l | Offline | 16-171-16-1 elf ua-wget | |
| 2026-06-10 06:27:27 | http://16.171.16.1/i686 | Offline | 16-171-16-1 elf mirai | |
| 2026-06-10 06:27:26 | http://16.171.16.1/armv5l | Offline | 16-171-16-1 elf ua-wget | |
| 2026-06-10 06:27:26 | http://16.171.16.1/mipsel | Online | 16-171-16-1 DDoSAgent elf ua-wget | |
| 2026-06-10 06:27:21 | http://16.171.16.1/armv6l | Offline | 16-171-16-1 elf ua-wget | |
| 2026-06-10 05:39:08 | http://16.171.16.1/arm | Offline | mirai | |
| 2026-06-10 05:39:07 | http://16.171.16.1/mips | Offline | mirai | |
| 2026-06-10 05:39:05 | http://16.171.16.1/run.sh | Offline | mirai |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-06-10 06:28:19 | 6d45e90c266e3268e1af13e23034a1d7625186a886f6ba6df129ba0baeb5c7f5 | elf | DDoSAgent | |
| 2026-06-10 06:27:27 | 3e126730583ee3fc728d8b77e22651f4446942c21c3be79a59ca230923aecc42 | elf | Mirai | |
| 2026-06-10 06:27:27 | b7bb3a5d16eafd1b9ef1a78f1803ea064b81f70b1a0c6e886383024d85e498f7 | elf | ||
| 2026-06-10 06:27:27 | 5687f54dab2014990fb8aef3a4645ac3405471bdd380e016afd89e98024811e3 | elf | ||
| 2026-06-10 06:27:27 | 3e126730583ee3fc728d8b77e22651f4446942c21c3be79a59ca230923aecc42 | elf | Mirai | |
| 2026-06-10 06:27:26 | 2617cce97aa2e70ac1871b46e4217567702a8c22979d5413ad46c28a150655aa | elf | ||
| 2026-06-10 06:27:26 | 89a51bb990e33e2020e036d1e3e788944f5ab0e4baa6f10427e250a618930092 | elf | DDoSAgent | |
| 2026-06-10 06:27:21 | 358cd9ae2ebc4a81b9dcb50d08195025208cb4861b5f90a989cc9a1580fa5b4a | elf | ||
| 2026-06-10 05:39:07 | fb103c725f1787f74de047cfa33c6dfbbca156792904206725e14b0843ba00ab | elf | ||
| 2026-06-10 05:39:07 | 2617cce97aa2e70ac1871b46e4217567702a8c22979d5413ad46c28a150655aa | elf |
SE