URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 161.97.163.222
Firstseen:2026-05-02 15:40:05 UTC
Total malware sites :19
Online malware sites :17 (89%)
Offline Malware sites :2 (11%)
Newest active malware site :2026-05-02 15:40:26 UTC
Oldest active malware site :2026-05-02 15:40:15 UTC (Age: 1 day, 14 hours, 58 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-05-02 15:40:15 161.97.163.222vmi3273283.contaboserver.netNot listedAS51167 CONTABO- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-02 23:10:07http://161.97.163.222/bins/jew.arm4Offlineua-wget botnetkiller
2026-05-02 23:10:07http://161.97.163.222/bins/wget.shOfflineua-wget botnetkiller
2026-05-02 15:40:26http://161.97.163.222/bins/jew.arm7Onlinearm elf mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:24http://161.97.163.222/bins/jew.mpslOnlineelf mips mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:24http://161.97.163.222/bins/jew.armOnlinearm elf mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:24http://161.97.163.222/bins/jew.arm6Onlinearm elf mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:22http://161.97.163.222/lOnlinemirai ext opendir sh ua-wget botnetkiller
2026-05-02 15:40:16http://161.97.163.222/wget.shOnlinemirai ext opendir sh ua-wget botnetkiller
2026-05-02 15:40:16http://161.97.163.222/jewn.shOnlinemirai ext opendir sh ua-wget botnetkiller
2026-05-02 15:40:16http://161.97.163.222/bins/jew.sh4Onlineelf mirai ext opendir SuperH ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/a/wget.shOnlinemirai ext opendir sh ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.arm5Onlinearm elf mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.m68kOnlineelf m68k mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.mipsOnlineelf mips mirai ext opendir ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.spcOnlineelf mirai ext opendir sparc ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.x86Onlineelf mirai ext opendir ua-wget x86 botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jew.ppcOnlineelf mirai ext opendir PowerPC ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/bins/jewn.shOnlinemirai ext opendir sh ua-wget botnetkiller
2026-05-02 15:40:15http://161.97.163.222/b/wget.shOnlinemirai ext opendir sh ua-wget botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-03 17:47:59d9edec0f728897c08cf06e12e7457a6ad245e9e1e03f35dcb345ac1f8f152b17shMirai
2026-05-02 15:40:26a39b9ca61cb94cecdb77632ed54c26e69626d3569f1ff04956de52f51db2474eelfMirai
2026-05-02 15:40:2406c3b54fbe5454c8db506947a902a6b9424a446650c1d13d319a4e970ab755b2elfMirai
2026-05-02 15:40:24f86ac036c6088bee14d1c2cde5362d2d9316ed79a5f25fa3364806825f86da53elfMirai
2026-05-02 15:40:2424112c8277c661c71002d06ace82e1ce89f455ad7aa5f3c19c7f4c76a804790aelfMirai
2026-05-02 15:40:22eb535afb4cddcb1ed15909bc78cd2da719c588f0e77f8da35d6b326ebe484bbeshMirai
2026-05-02 15:40:1612cb2fc108d6e276c9b142a2d5ca887a77cd6fd4e6ea4eb6d735505577ee02c5shMirai
2026-05-02 15:40:1612cb2fc108d6e276c9b142a2d5ca887a77cd6fd4e6ea4eb6d735505577ee02c5shMirai
2026-05-02 15:40:157755520fc3fc74c815f972a54f9e7c7ccae95c8c4cd4c1f5043a903af222e711elfMirai
2026-05-02 15:40:1535e068d9614a0a2d71ac4a935b45ff11d9e674c124da14e0df092d72003f0d0eelfMirai
2026-05-02 15:40:157ddbd84d464d3924ed0fb31c638ac95d3a83c367f0d428830d4cacfe36c2e1ceelfMirai
2026-05-02 15:40:15090106580395f02f8224c2186d322f46929d8ebdebdb86dd7bb59ab4d0cf4313elfMirai
2026-05-02 15:40:158dfa5e80f824aac1b8f126aa11d0fb6e62954c3a84ae94204a261895e5b75c2felfMirai
2026-05-02 15:40:1543999e54b0a43902d3b97409eeee33b6eb18586b31d4a28cb8978bc0cd6dcf40elfMirai
2026-05-02 15:40:15ec1f7f42a7a4634251b22b1b681a798386295a44cab22792d6ba5bc2bb3cb966elfMirai
2026-05-02 15:40:1412cb2fc108d6e276c9b142a2d5ca887a77cd6fd4e6ea4eb6d735505577ee02c5shMirai
2026-05-02 15:40:1412cb2fc108d6e276c9b142a2d5ca887a77cd6fd4e6ea4eb6d735505577ee02c5shMirai
2026-05-02 15:40:1412cb2fc108d6e276c9b142a2d5ca887a77cd6fd4e6ea4eb6d735505577ee02c5shMirai