URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 168.121.168.84
Firstseen:2025-10-04 04:20:19 UTC
Total malware sites :14
Online malware sites :11 (79%)
Offline Malware sites :3 (21%)
Newest active malware site :2025-10-04 05:11:26 UTC
Oldest active malware site :2025-10-04 04:20:22 UTC (Age: 7 months, 26 days, 19 hours, 11 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-04 04:20:22 168.121.168.84Not listedAS52545 BJ_NET_Provedor_de_Internet_Ltda._-_ME- BRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-04 05:11:26http://168.121.168.84:8081/info.zipOnlineCoinMiner zip Riordz
2025-10-04 05:08:17http://168.121.168.84:8081/Photo.scrOnlineCoinMiner Riordz
2025-10-04 05:06:02http://168.121.168.84:8081/Photo.lnkOnlineCoinMiner Riordz
2025-10-04 05:05:09http://168.121.168.84:8081/AV.lnkOnlineCoinMiner Riordz
2025-10-04 04:59:10http://168.121.168.84/Photo.scrOfflineCoinMiner Riordz
2025-10-04 04:51:11http://168.121.168.84/AV.scrOfflineCoinMiner Riordz
2025-10-04 04:46:49http://168.121.168.84:8081/Video.lnkOnlineCoinMiner Riordz
2025-10-04 04:44:20http://168.121.168.84/Video.scrOnlineCoinMiner Riordz
2025-10-04 04:37:11http://168.121.168.84:8081/AV.scrOfflineCoinMiner Riordz
2025-10-04 04:35:37http://168.121.168.84:8081/Video.scrOnlineCoinMiner Riordz
2025-10-04 04:34:26http://168.121.168.84/info.zipOnlineCoinMiner zip Riordz
2025-10-04 04:27:04http://168.121.168.84/Video.lnkOnlineCoinMiner Riordz
2025-10-04 04:22:16http://168.121.168.84/AV.lnkOnlineCoinMiner Riordz
2025-10-04 04:20:22http://168.121.168.84/Photo.lnkOnlineCoinMiner Riordz

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-28 08:23:285d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaexeCoinMiner
2026-05-28 02:01:165d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaexeCoinMiner
2026-05-28 01:58:225d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaexeCoinMiner
2026-05-28 01:57:125d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaexeCoinMiner
2025-10-04 05:11:26b914abc696286a639a847d2e3a4a36ff682f30a87b08c4ffc61f2e0cf5e7ec5fzip  
2025-10-04 05:08:17807126cbae47c03c99590d081b82d5761e0b9c57a92736fc8516cf41bc564a7dexe CoinMiner
2025-10-04 05:06:0200401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk  
2025-10-04 05:05:0900401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk  
2025-10-04 04:59:10807126cbae47c03c99590d081b82d5761e0b9c57a92736fc8516cf41bc564a7dexe CoinMiner
2025-10-04 04:51:11af94ddf7c35b9d9f016a5a4b232b43e071d59c6beb1560ba76df20df7b49ca4cexe CoinMiner
2025-10-04 04:46:4800401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk  
2025-10-04 04:44:20af94ddf7c35b9d9f016a5a4b232b43e071d59c6beb1560ba76df20df7b49ca4cexe CoinMiner
2025-10-04 04:37:11af94ddf7c35b9d9f016a5a4b232b43e071d59c6beb1560ba76df20df7b49ca4cexe CoinMiner
2025-10-04 04:35:37af94ddf7c35b9d9f016a5a4b232b43e071d59c6beb1560ba76df20df7b49ca4cexe CoinMiner
2025-10-04 04:34:26b914abc696286a639a847d2e3a4a36ff682f30a87b08c4ffc61f2e0cf5e7ec5fzip  
2025-10-04 04:27:0400401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk  
2025-10-04 04:22:1600401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk  
2025-10-04 04:20:2100401651af3194ede5157004b6dbe1edf836a94ca182221f2c034201fe55e4dclnk