URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 161.248.238.20
Firstseen:2025-05-10 02:55:03 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-10 02:55:13 161.248.238.20SBL674936AS150895 EZTECH-VN- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-05-10 11:17:13http://161.248.238.20/wget.shOfflinemirai ext sh ua-wget NDA0E
2025-05-10 02:55:15http://161.248.238.20/mpslOfflineelf mirai ext tolisec
2025-05-10 02:55:15http://161.248.238.20/ppcOfflineelf mirai ext tolisec
2025-05-10 02:55:14http://161.248.238.20/sh4Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/arm5Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/arm6Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/x86Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/armOfflineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/m68kOfflineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/x86_64Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/arm7Offlineelf mirai ext tolisec
2025-05-10 02:55:13http://161.248.238.20/mipsOfflineelf mirai ext tolisec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-10 12:08:216604b4f132ebfdbf424982f0fb1decd338528a1c351ef409f01c14d5ab048201elfMirai
2025-05-10 11:56:5426f2fa26f7e92d6e395add649623e975baf3bdc0daeb1cce0e71bf62d4150d2felfMirai
2025-05-10 11:38:20e9faf47cb75df4be265a97065ec8d5b786ff7fedf881b99119bf20eb3f6772fbelfMirai
2025-05-10 11:19:20f2345b8170a71cc6be7e0a19600a548c0d089dbd8452023f6f56b1129b8dcc78elfMirai
2025-05-10 11:17:138901320413776f43a0e6325662ec9ecf41fd420c430aa5b810cc183d6b7164e6shMirai
2025-05-10 11:03:048ab38316dd9c8b70c1e4d601770ba222b4c5f342a772681e1763910be14170c4elfMirai
2025-05-10 11:00:219fd108226aab5d7005fe4303e69b5fbf4b1ff270613c1685d116daee9c2e8528elfMirai
2025-05-10 10:38:01e68562225a4e166f921edd78639758bfcbcce0264d60bb2fd18eb5d4a3071df7elfMirai
2025-05-10 10:31:061287fbbd15e8d6cc65a79981ef8cb83d7c13c126eb9787de9c7e9c5004bad361elfMirai
2025-05-10 10:20:4466106fd382ec4be451b29281c7db9d1ecb85f094fd08038dde2c04a34b4e1ddbelfMirai
2025-05-10 10:19:399e7a10dc18a47be06fd12b7e4ff446dcc41f3cdd288d03d515f4c575b3e3a9a7elfMirai
2025-05-10 10:10:3077f557c5356d83a4a842513ec5c6fcacec8296d089885f9d1b14acc177ece082elfMirai
2025-05-10 02:55:1579a64b9e6985d4a276d772a903aaa2b2261db35ccdab00994164655fbef92f2delfMirai
2025-05-10 02:55:14b32817fbf7141c4b889b398bfab58bea5d6447c5507952cbb8ed71fbb1b5864eelfMirai
2025-05-10 02:55:14d18c1c9a41cfb4cd983c16f9c6f375ca81062c1f4beba9c151d014efbd201467elfMirai
2025-05-10 02:55:1307c012325a2096b916ebcf2465185b1235ed43590873f089264f52809fdfacb9elfMirai
2025-05-10 02:55:13621f48ee214a62c1082d136c9e344a4b30700a934f0bb26b8e6aaa8d7c4bf04delfMirai
2025-05-10 02:55:133c0cd3910e7aabbc42c927ffbed4004b5d5112241ba20ee7f0233a76a60dca51elfMirai
2025-05-10 02:55:1340151d2e6e7e06951738801c7b5d8d621ace55a8ea0c8d1e462d88a9a1ebea6aelfMirai
2025-05-10 02:55:1326ee97360c24eaf38aa134edcd053c07ccddca24c6e818cb16f7d9ccb44c8574elfMirai
2025-05-10 02:55:137a429c5c6d50a9dcfd4acfefbf2f4f655fa94c02e440c3b65ac8e35c57de3dd6elfMirai
2025-05-10 02:55:13bae25d63a88fc608888d8b39431bfc3cff2c57212b5ea67abebdc024fbf2e694elfMirai
2025-05-10 02:55:12124da2098d04e72cdbf47422e034fe486e0108318176514dc7cc5d47d6dcc6faelfMirai