URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 161.97.74.69
Firstseen:2025-08-20 21:02:03 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-20 21:02:16 161.97.74.69vmi2702901.contaboserver.netNot listedAS51167 CONTABO- FRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-21 12:06:17http://161.97.74.69/systemcl/arcOfflineelf ua-wget abuse_ch
2025-08-21 07:51:17http://161.97.74.69/systemcl/sh4Offlineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:26http://161.97.74.69/systemcl/spcOfflineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:25http://161.97.74.69/c.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-21 07:48:25http://161.97.74.69/w.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-21 07:48:24http://161.97.74.69/test.shOfflinesh ua-wget BlinkzSec
2025-08-21 07:48:24http://161.97.74.69/systemcl/arm5Offlineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:24http://161.97.74.69/systemcl/x86_64Offlineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:13http://161.97.74.69/wget.shOfflinemirai ext sh ua-wget BlinkzSec
2025-08-21 07:48:12http://161.97.74.69/systemcl/ppcOfflineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:12http://161.97.74.69/systemcl/arm7Offlineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:12http://161.97.74.69/systemcl/m68kOfflineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:12http://161.97.74.69/systemcl/mpslOfflineelf mirai ext ua-wget BlinkzSec
2025-08-21 07:48:10http://161.97.74.69/systemcl/arm6Offlineelf mirai ext ua-wget BlinkzSec
2025-08-20 21:02:17http://161.97.74.69/systemcl/armOffline32-bit elf mirai ext Mozi ext threatquery
2025-08-20 21:02:16http://161.97.74.69/systemcl/x86Offline32-bit elf mirai ext Mozi ext threatquery
2025-08-20 21:02:16http://161.97.74.69/systemcl/mipsOffline32-bit elf mirai ext Mozi ext threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-21 07:51:17b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2elfMirai
2025-08-21 07:48:262b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54celfMirai
2025-08-21 07:48:25770ae0b3092fd00fed8231d5d72c203305f580a0610a3bb27f3ff6192092c5aeshMirai
2025-08-21 07:48:2447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230elfMirai
2025-08-21 07:48:24467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecbelfMirai
2025-08-21 07:48:245cea6237f2e47265f9bd38c0c907adeab2a5e4000e4770f6ad1c757955a95059sh 
2025-08-21 07:48:2427ae9a46d723531b26452f5ec169ef2a90074d5b206ec617f08bb0a9e8405c15shMirai
2025-08-21 07:48:1219abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659elfMirai
2025-08-21 07:48:121745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524elfMirai
2025-08-21 07:48:12abfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955eelfMirai
2025-08-21 07:48:12163a2c04fa5a1a8607a3aa00791c044bf68f7b20d610d555f9991aca861028acshMirai
2025-08-21 07:48:117365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242elfMirai
2025-08-21 07:48:107a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104elfMirai
2025-08-20 21:02:17a2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9elfMirai
2025-08-20 21:02:162e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72elfMirai
2025-08-20 21:02:16ad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4elfMirai