URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 160.191.245.152
Firstseen:2025-03-07 13:45:02 UTC
Total malware sites :31
Online malware sites :0 (0%)
Offline Malware sites :31 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-07 13:45:03 160.191.245.152Not listedAS153416 DTDMVNCLOUD-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-15 10:40:33http://160.191.245.152/w.shOfflinesh NDA0E
2025-03-15 10:40:33http://160.191.245.152/wget.shOfflinesh NDA0E
2025-03-15 10:40:33http://160.191.245.152/c.shOfflinesh NDA0E
2025-03-14 14:26:07http://160.191.245.152/bins/spcOfflineelf mirai ext tolisec
2025-03-14 14:26:07http://160.191.245.152/bins/m68kOfflineelf mirai ext tolisec
2025-03-14 14:26:07http://160.191.245.152/bins/mpslOfflineelf mirai ext tolisec
2025-03-14 14:26:07http://160.191.245.152/bins/mipsOfflineelf mirai ext tolisec
2025-03-14 14:26:07http://160.191.245.152/bins/armOfflineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/arm5Offlineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/arm6Offlineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/arm7Offlineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/ppcOfflineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/sh4Offlineelf mirai ext tolisec
2025-03-14 14:26:06http://160.191.245.152/bins/x86Offlineelf mirai ext tolisec
2025-03-11 08:34:05http://160.191.245.152/ohshit.shOfflinemirai ext sh BlinkzSec
2025-03-10 19:42:05http://160.191.245.152/debug.dbgOfflineelf mirai ext ua-wget ClearlyNotB
2025-03-07 13:45:08http://160.191.245.152/dlr/blah.spcOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.arm5Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.sh4Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.arcOfflineelf opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.mpslOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.arm6Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.armOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.x86_64Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.ppcOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.arm7Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.mipsOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:06http://160.191.245.152/dlr/blah.m68kOfflineelf mirai ext opendir abuse_ch
2025-03-07 13:45:05http://160.191.245.152/dlr/blah.x86Offlineelf mirai ext opendir abuse_ch
2025-03-07 13:45:04http://160.191.245.152/dlr/blah.i468Offlineelf opendir abuse_ch
2025-03-07 13:45:03http://160.191.245.152/dlr/blah.i686Offlineelf opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-14 14:26:076b5d2ee2c0bb8af1ec9ee6df0a3706f8319034025e91d3e062fe378547179546elfMirai
2025-03-14 14:26:073736659ec9a1d8f7311588258c351e28ed0b2ccae8ad23bc73808cdd1f0abb19elfMirai
2025-03-14 14:26:07ba6631c12fb8d1a5f2341536c1cbcfdcb5ca10ff490527c446c3041519d20682elfMirai
2025-03-14 14:26:07c47330f1a40b081f829326ed9f3179dff03e51c2c429a840d36cc1dc8f738fd0elfMirai
2025-03-14 14:26:0718ac321e5635275c0b902577c2f8570ee54dedd317cd3e2581209fdc0b1e7c33elfMirai
2025-03-14 14:26:06634cd76e63dee06f81c65edea557d082817771b202271c556107b7b9b36fa71celfMirai
2025-03-14 14:26:0684371343532078bd13d1e9f397d14430a9f03417b0b0c1334e7b6f468cd12689elfMirai
2025-03-14 14:26:06fde141ff39e54ba71947c81588dd620bd6abc0188d2461980985ad10ba5c0bbfelfMirai
2025-03-14 14:26:066f7fb99aa7998ce92396544874c6e8322954e6d8a11b5e0e79bdc5a3c9f51f46elfMirai
2025-03-14 14:26:0621683c52f6d34bff5d92c9e31423e6e61d0e003b04f8d8b6bf61bad532185c88elfMirai
2025-03-14 14:26:06d1b6dfcbfd3ccbedc36ae4f66e87957d8f5f9e67f15bb1d59292d4b15d754aefelfMirai
2025-03-11 14:13:5229eae7a3fc0f8f73775f7202b9b7972c62a40320b7331588db4e8cf560749719shMirai
2025-03-11 08:34:052318d5b892bf16e67ddff911ded3f8d55d691cab7f7fdb7766b2e93f063665c4shMirai
2025-03-10 19:42:053a87f9a9f0ac2407e7b413926cc23d47c5e17d4ab554bcbb221661dbc0feab9aelfMirai
2025-03-07 13:45:0804cb1630dc7bf2fbcfa7455c19d89b847d2da9fed1452713219056c2e2d46cddelfMirai
2025-03-07 13:45:0651288104da90512c06fa48467a8116365982035cfe8e8b9ce552d0547562e867elfMirai
2025-03-07 13:45:0644891b0983075ae2003f11fcd1032b84880290c5dc1dd616175ddb8b8e97f201elfMirai
2025-03-07 13:45:06ae40589ca011bbeeab71412a1d1ecaab9a8f5757815c11832a1cb775691d8b58elfMirai
2025-03-07 13:45:066b8faa24f772912d3db092f4c1d8f1201b43f676c750c0a707af7b0ddab581f0elfMirai
2025-03-07 13:45:065f612b06a6807b8e5be3470a5fffe2341278910fd5b04fc558bb263ee9217fa9elfMirai
2025-03-07 13:45:061305be49b5c56dcf02fe33cf6517e1eeb98f7cbdcca5126187f15c974d27b445elfMirai
2025-03-07 13:45:067942fbd002e0b1a152f368e0831a1206504063ec2a8556bcb153cf6dac29c79belfMirai
2025-03-07 13:45:06148c15fe0313e85c686eb12040e7110409dee4734909e82fce8f987e2b3ba252elfMirai
2025-03-07 13:45:061e74b70fafd03b372bd8f0b932ae682ab2ea7b73f69744dfc26e24385f23f569elfMirai
2025-03-07 13:45:06cbc0a3f10117b1ce2394feec34e60f8ddfdc4e2ebbfc2ede0497c7223449c8eaelfMirai
2025-03-07 13:45:052ce9fb3fae4dd2c0540e15c416d79a33933b714551d6016b28ddaa0f52a06913elfMirai